Executive brief
A privacy vulnerability in Apple iOS and iPadOS could allow someone with physical access to a device to view restricted content directly from the lock screen. This bypasses intended security restrictions that should keep sensitive information hidden until the device is unlocked. Users should update to the latest software version to ensure their private data remains protected from unauthorized local viewing.
Technical details
A privacy issue exists in iOS and iPadOS where restricted content may be visible from the lock screen without proper authentication. The vulnerability stems from insufficient checks during lock screen state management. An attacker with physical access to the device could exploit this to bypass privacy preferences and view sensitive data. Apple addressed this issue in iOS 26.5 and iPadOS 26.5 by implementing improved validation checks.
Affected products
- Apple iOS Before 26.5
- Apple iPadOS Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched