Junglewise Threat Intelligence

CVE-2026-86924: Apple iOS and iPadOS memory corruption via malicious accessory

CVE-2026-86924 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Executive brief

iOS and iPadOS devices handle input from physical accessories (chargers, adapters, etc.) to control system behavior. A memory corruption vulnerability allows a malicious accessory to trigger an unexpected system crash, causing temporary unavailability and poor user experience. The flaw affects millions of devices and requires physical device access to exploit.

Technical details

A memory corruption vulnerability exists in the accessory input handling subsystem of iOS and iPadOS due to insufficient input validation. When a maliciously crafted physical accessory communicates with the device, it can trigger an out-of-bounds memory write or similar memory safety violation. The attack requires the attacker to have physical control of a device and connect a malicious accessory, resulting in unexpected process termination (denial of service). The vulnerability has been patched in iOS 27, iPadOS 27, iOS 26.7, and iPadOS 26.7 through improved input validation on accessory data.

Affected products

  • Apple iOS before 26.7 and 27
  • Apple iPadOS before 26.7 and 27

Timeline

  • 2026-09-14: disclosed: CVE-2026-86924 published; patches released for iOS 27, iPadOS 27, iOS 26.7, iPadOS 26.7
  • 2026-09-14: patched: Fixed in iOS 27, iPadOS 27, iOS 26.7, iPadOS 26.7

References

Related threats