Executive brief
Apple's operating systems use certificate validation to ensure secure communication between devices and servers. A flaw in this validation allows an attacker with a compromised intermediate certificate authority to issue fraudulent certificates with arbitrary permissions, enabling man-in-the-middle attacks and unauthorized access to sensitive communications. This affects iPhones, iPads, Mac computers, Apple Watches, and other Apple devices.
Technical details
A certificate validation vulnerability exists in Apple's certificate handling logic affecting multiple operating systems. The issue allows an attacker who has compromised an intermediate certificate authority to issue certificates with arbitrary extended key usages, bypassing normal certificate validation controls. This is a critical flaw because extended key usage (EKU) extensions are meant to restrict what purposes a certificate can be used for; arbitrary EKUs enable unauthorized use cases. The vulnerability is present across iOS/iPadOS, macOS, tvOS, visionOS, and watchOS platforms. Patches were released on September 14, 2026 across all affected platforms through their latest major and minor versions.
Affected products
- Apple iOS before 27, before 26.7
- Apple iPadOS before 27, before 26.7
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
- Apple tvOS before 27
- Apple visionOS before 27
- Apple watchOS before 27
Timeline
- 2026-09-14: disclosed: Vulnerability details released with security updates
- 2026-09-14: patched: Patches released for all affected platforms