Junglewise Threat Intelligence

CVE-2026-86887: Apple iOS privacy issue allowing app bypass of user preferences

CVE-2026-86887 · Severity: low · CVSS 3.3 · Published 2026-09-14

Technologies: Apple Iphone Os, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

Apple's iOS and related platforms contain a privacy vulnerability that allows malicious apps to circumvent user privacy preferences and access sensitive data without proper authorization. This could enable apps to collect personal information that users intentionally restricted, leading to unauthorized data exposure and privacy violations.

Technical details

A privacy issue in iOS, iPadOS, and visionOS allowed applications to bypass Privacy preferences through improper handling of sensitive data exposure. The vulnerability was addressed by removing sensitive data and improving privacy enforcement mechanisms. The issue affects the core system's ability to enforce user-configured privacy restrictions, allowing local apps with standard permissions to access protected information. Patches are available in iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, and visionOS 27 released on September 14, 2026.

Affected products

  • Apple iOS before 26.7, before 27
  • Apple iPadOS before 26.7, before 27
  • Apple visionOS before 27

Timeline

  • 2026-09-14: disclosed: CVE-2026-86887 disclosed; patches released in iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, visionOS 27
  • 2026-09-14: patched

References

Related threats