Junglewise Threat Intelligence

CVE-2026-86879: Apple iOS and iPadOS input validation denial-of-service

CVE-2026-86879 · Severity: medium · CVSS 6.5 · Published 2026-09-14

Technologies: Apple Iphone Os, Apple iPadOS. Vendors: Apple.

Executive brief

iOS and iPadOS are Apple's mobile operating systems used by hundreds of millions of users worldwide. A remote attacker can trigger a denial-of-service condition by sending maliciously crafted input, causing the device to become unresponsive or crash. Apple has patched this issue in iOS 27 and iPadOS 27.

Technical details

This is a denial-of-service vulnerability in iOS and iPadOS caused by insufficient input validation. A remote attacker can craft malicious input that bypasses validation checks and triggers unexpected process termination or system instability. The vulnerability is network-reachable and does not require user authentication or device-level privileges. Apple addressed the issue by implementing improved input validation logic in iOS 27 and iPadOS 27, released on September 14, 2026.

Affected products

  • Apple iOS before 27
  • Apple iPadOS before 27

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: iOS 27 and iPadOS 27 released

References

Related threats