Junglewise Threat Intelligence

CVE-2026-86885: Apple iOS input validation issue in wireless radio component

CVE-2026-86885 · Severity: medium · CVSS 6.5 · Published 2026-09-14

Technologies: Apple Iphone Os, Apple iPadOS. Vendors: Apple.

Executive brief

iOS and iPadOS devices can be remotely disrupted by an attacker within radio range sending maliciously crafted wireless signals. This vulnerability allows an attacker to cause the device to crash unexpectedly, resulting in loss of availability without requiring any user interaction or authentication. The issue affects a wide range of iPhone and iPad models.

Technical details

An input validation vulnerability exists in the wireless radio processing component of iOS and iPadOS, where maliciously crafted radio signals are not properly validated before processing. An attacker in radio range can send specially crafted wireless packets to trigger unexpected system termination. No user interaction or authentication is required; the attack succeeds purely through network proximity and crafted radio frames. The vulnerability was patched in iOS 27 and iPadOS 27 through improved input validation in the radio signal processing stack.

Affected products

  • Apple iOS before 27
  • Apple iPadOS before 27

Timeline

  • 2026-09-14: disclosed: iOS 27 and iPadOS 27 released with patch
  • 2026-09-14: patched: Fixed in iOS 27 and iPadOS 27

References

Related threats