Junglewise Threat Intelligence

CVE-2026-43674: Apple iOS authentication bypass in Wi-Fi credential storage

CVE-2026-43674 · Severity: medium · CVSS 4.6 · Published 2026-09-14

Technologies: Apple Iphone Os, Apple iPadOS. Vendors: Apple.

Executive brief

iOS and iPadOS devices store Wi-Fi network passwords locally for automatic reconnection. This vulnerability allows an attacker with physical access to an unlocked device to view those saved Wi-Fi passwords without requiring additional authentication, potentially exposing network credentials and enabling unauthorized network access.

Technical details

An authentication issue in iOS and iPadOS Wi-Fi credential management allows unauthorized disclosure of stored network passwords. The vulnerability stems from improper state management in the authentication mechanism protecting access to saved Wi-Fi configurations. An attacker requires physical access to an unlocked device but no additional authentication or user interaction. Upon exploitation, saved Wi-Fi passwords become accessible without proper authorization checks. Apple addressed the issue in iOS 27 and iPadOS 27 through improved state management.

Affected products

  • Apple iOS before 27
  • Apple iPadOS before 27

Timeline

  • 2026-09-14: disclosed: CVE-2026-43674 disclosed with iOS 27 and iPadOS 27 release
  • 2026-09-14: patched: Fixed in iOS 27 and iPadOS 27

References

Related threats