Executive brief
Apple's iOS, iPadOS, and macOS operating systems contain a cryptographic flaw that allows an attacker positioned on the network path to intercept and modify encrypted traffic in transit. An attacker with privileged network access (such as on a shared WiFi network or compromised ISP) could read or alter sensitive communications between a user's device and remote services. This affects millions of users across iPhones, iPads, and Mac computers.
Technical details
A cryptographic integrity check vulnerability exists in Apple's network communication stack. The flaw allows an attacker in a privileged network position (man-in-the-middle) to modify network traffic without detection because integrity verification was insufficient. The attack requires network-level access but does not require authentication or user interaction. An attacker can eavesdrop on or alter encrypted traffic, potentially compromising confidentiality and integrity of data in transit. Apple addressed this issue with improved integrity checks and released patches in iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, and watchOS 27 (all released September 14, 2026).
Affected products
- Apple iOS before 27
- Apple iPadOS before 27
- Apple macOS before Golden Gate 27
- Apple tvOS before 27
- Apple watchOS before 27
Timeline
- 2026-09-14: disclosed: CVE-2026-84533 disclosed; patched in iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27