Executive brief
iOS and iPadOS devices can be remotely disrupted by an attacker within radio range sending maliciously crafted wireless signals. This vulnerability allows an attacker to cause the device to crash unexpectedly, resulting in loss of availability without requiring any user interaction or authentication. The issue affects a wide range of iPhone and iPad models.
Technical details
An input validation vulnerability exists in the wireless radio processing component of iOS and iPadOS, where maliciously crafted radio signals are not properly validated before processing. An attacker in radio range can send specially crafted wireless packets to trigger unexpected system termination. No user interaction or authentication is required; the attack succeeds purely through network proximity and crafted radio frames. The vulnerability was patched in iOS 27 and iPadOS 27 through improved input validation in the radio signal processing stack.
Affected products
- Apple iOS before 27
- Apple iPadOS before 27
Timeline
- 2026-09-14: disclosed: iOS 27 and iPadOS 27 released with patch
- 2026-09-14: patched: Fixed in iOS 27 and iPadOS 27