Executive brief
iOS and iPadOS devices store Wi-Fi network passwords locally for automatic reconnection. This vulnerability allows an attacker with physical access to an unlocked device to view those saved Wi-Fi passwords without requiring additional authentication, potentially exposing network credentials and enabling unauthorized network access.
Technical details
An authentication issue in iOS and iPadOS Wi-Fi credential management allows unauthorized disclosure of stored network passwords. The vulnerability stems from improper state management in the authentication mechanism protecting access to saved Wi-Fi configurations. An attacker requires physical access to an unlocked device but no additional authentication or user interaction. Upon exploitation, saved Wi-Fi passwords become accessible without proper authorization checks. Apple addressed the issue in iOS 27 and iPadOS 27 through improved state management.
Affected products
- Apple iOS before 27
- Apple iPadOS before 27
Timeline
- 2026-09-14: disclosed: CVE-2026-43674 disclosed with iOS 27 and iPadOS 27 release
- 2026-09-14: patched: Fixed in iOS 27 and iPadOS 27