Junglewise Threat Intelligence

CVE-2026-86886: Apple iOS path traversal in system file access

CVE-2026-86886 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple Iphone Os, Apple watchOS, Apple iPadOS. Vendors: Apple.

Executive brief

A path traversal vulnerability in iOS and iPadOS allows malicious apps to bypass file system protections and modify protected system files. An attacker could use this flaw to alter critical system components, potentially compromising device integrity, stability, and security. Apple patched this in iOS 26.7, iPadOS 26.7, and later versions.

Technical details

A path traversal vulnerability allows an app to bypass file system access controls through inadequate input validation. The vulnerability exists in iOS and iPadOS, permitting a local app to craft malicious file paths (using techniques like ../ sequences) to access and modify protected system files outside the intended application sandbox. Exploitation requires the malicious app to be installed on the device (local attack vector). The fix involves improved input validation to prevent path traversal sequences. Apple addressed this in iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, and watchOS 27.

Affected products

  • Apple iOS before 26.7 and before 27
  • Apple iPadOS before 26.7 and before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Fixed in iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, and watchOS 27

References

Related threats