Junglewise Threat Intelligence

CVE-2026-86878: Apple iOS and iPadOS permissions issue allowing sensitive data access

CVE-2026-86878 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple Iphone Os, Apple iPadOS. Vendors: Apple.

Executive brief

Apple's iOS and iPadOS operating systems contained a permissions vulnerability that could allow a malicious app to access sensitive user data without proper authorization. This issue was patched in iOS 27 and iPadOS 27 released on September 14, 2026. The vulnerability affects millions of iPhone and iPad users, potentially exposing personal information to unauthorized apps.

Technical details

This is a permissions bypass vulnerability in Apple's iOS and iPadOS platforms (CVE-2026-86878) where insufficient access controls allowed applications to access sensitive user data. The vulnerability was addressed by implementing additional restrictions to the permissions framework. The bug required a malicious app to be installed on the device (local attack vector) to exploit it. Apple patched the issue by restricting how apps can query or access protected user data. The fix was released on September 14, 2026 in iOS 27 and iPadOS 27.

Affected products

  • Apple iOS before 27
  • Apple iPadOS before 27

Timeline

  • 2026-09-14: patched: Fixed in iOS 27 and iPadOS 27
  • 2026-09-14: disclosed: Published on Apple Security Updates page

References

Related threats