CVE-2026-86890
Received Received - Intake

Physical Access Bypass in iOS and iPadOS

Vulnerability report for CVE-2026-86890, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: Apple Inc.

Description

A logic issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27. An attacker with physical access to a locked device may be able to view sensitive user information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
apple ios to 26.7 (inc)
apple ipados to 26.7 (inc)
apple ios 27
apple ipados 27

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a logic issue in iOS and iPadOS that allows an attacker with physical access to a locked device to view sensitive user information. It was addressed with improved checks in iOS 26.7, iPadOS 26.7, iOS 27, and iPadOS 27.

Detection Guidance

This vulnerability requires physical access to a locked device, so detection on a network is not applicable. Check if your iOS or iPadOS device is running a vulnerable version (below iOS 26.7/iPadOS 26.7 or iOS 27/iPadOS 27).

Impact Analysis

If someone gains physical access to your locked iOS or iPadOS device, they may be able to bypass security measures and view your sensitive information without unlocking the device.

Mitigation Strategies

Update your iOS or iPadOS device to the latest version (iOS 26.7/iPadOS 26.7 or iOS 27/iPadOS 27) to address the issue. Ensure the device remains locked when not in use.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86890. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart