Executive brief
iOS and iPadOS Accessibility framework contains a privacy vulnerability that allows third-party apps to access sensitive user data through improved file handling. An attacker can exploit this by crafting a malicious app to read data the user did not intend to share, potentially exposing personal information, contacts, or documents.
Technical details
This vulnerability is a privacy issue in iOS and iPadOS Accessibility component addressed through improved file handling mechanisms. The vulnerability allows an app to access sensitive user data; the specific attack vector and root cause are not detailed in the advisory but involve improper isolation or permissions in the Accessibility framework's file operations. The issue requires local app installation and runs with the app's existing permissions. Apple patched this issue in iOS 27 and iPadOS 27 released on September 14, 2026.
Affected products
- Apple iOS before 27
- Apple iPadOS before 27
Timeline
- 2026-09-14: disclosed: CVE-2026-86883 disclosed with iOS 27 and iPadOS 27 release
- 2026-09-14: patched: Fixed in iOS 27 and iPadOS 27