Executive brief
A vulnerability in iPhone Mirroring could allow an individual with physical access to a device to view sensitive user data. This issue affects iPhones and iPads and was caused by improper state management during the mirroring process. Apple has released updates to address this flaw by improving how the system handles state transitions.
Technical details
A vulnerability in iPhone Mirroring on iOS and iPadOS was identified where sensitive user data could be exposed due to improper state management. An attacker with physical access to the device could exploit this flaw to bypass intended data protections during a mirroring session. The root cause was addressed by improving state management logic within the operating system. This issue is resolved in iOS 26.6 and iPadOS 26.6.
Affected products
- Apple iOS before 26.6
- Apple iPadOS before 26.6
Timeline
- 2026-07-27: disclosed
- 2026-07-27: patched