Executive brief
A path traversal vulnerability in iOS and iPadOS allows an attacker with physical access to a trust-paired device to read and write arbitrary files on the system. This could enable unauthorized access to sensitive user data, personal documents, photos, and credentials stored on the device, potentially compromising all information protected by the operating system's file access controls.
Technical details
This is a path traversal vulnerability that was fixed through improved path validation in the iOS/iPadOS file system handling code. The vulnerability requires physical access to a device that has been previously trust-paired with the attacker's device, allowing the attacker to circumvent normal file access restrictions and traverse the file system hierarchy to access arbitrary files for both reading and writing. The issue affects iOS 26.7 and earlier, as well as iOS 27 prior to the patch release. The vulnerability has been patched in iOS 26.7 and iOS 27 (released September 14, 2026) with enhanced path validation mechanisms.
Affected products
- Apple iOS 26.7 and earlier, 27 pre-patch
- Apple iPadOS 26.7 and earlier, 27 pre-patch
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched: Fixed in iOS 26.7, iPadOS 26.7, iOS 27, and iPadOS 27