Executive brief
iOS and iPadOS contain a logic flaw that may allow an attacker with physical access to a locked device to view sensitive user information. This affects millions of iPhones and iPads. An attacker would need to physically possess the device but could potentially access personal data, photos, messages, or other private information without knowing the device passcode.
Technical details
A logic issue in iOS and iPadOS security controls allows information disclosure through a flaw in the device lock mechanism. The vulnerability requires physical access to the device and is addressed through improved checks in the authentication or access control flow. The precise attack vector is not fully disclosed, but the fix was applied to iOS 26.7, iPadOS 26.7, iOS 27, and iPadOS 27. The vulnerability allows viewing of sensitive user information despite the device being in a locked state.
Affected products
- Apple iOS before 26.7 and before 27
- Apple iPadOS before 26.7 and before 27
Timeline
- 2026-09-14: patched: Fixed in iOS 26.7, iPadOS 26.7, iOS 27, and iPadOS 27