Junglewise Threat Intelligence

CVE-2026-84551: Apple iOS and iPadOS network restriction bypass

CVE-2026-84551 · Severity: medium · CVSS 4.4 · Published 2026-09-14

Technologies: Apple macOS, Apple Iphone Os, Apple watchOS, Apple Visionos, Apple iPadOS, Apple macOS Golden Gate. Vendors: Apple.

Executive brief

A logic flaw in iOS and iPadOS network controls allows malicious apps to circumvent network restrictions that are intended to protect user privacy and data. An attacker could craft an app that bypasses these security boundaries, enabling unauthorized network access to sensitive user information or external services. This vulnerability affects iPhone and iPad devices running affected versions.

Technical details

A logic issue in iOS and iPadOS network validation allows apps to bypass network restrictions through improved validation. The vulnerability is a logic flaw in network policy enforcement, addressable through improved state validation. The attack vector is local (requires the malicious app to be installed on the device). An attacker can craft a malicious app that bypasses network restrictions, potentially accessing restricted network resources or user data. Apple has patched this issue in iOS 27, iPadOS 27, and corresponding releases of macOS Golden Gate 27, visionOS 27, and watchOS 27 released on September 14, 2026.

Affected products

  • Apple iOS before 27
  • Apple iPadOS before 27
  • Apple macOS Golden Gate before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched

References

Related threats