Full Disclosure mailing list archives

APPLE-SA-09-14-2026-1 iOS 27 and iPadOS 27


From: Apple Product Security via Fulldisclosure <fulldisclosure () seclists org>
Date: Mon, 14 Sep 2026 14:46:43 -0700

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

APPLE-SA-09-14-2026-1 iOS 27 and iPadOS 27

iOS 27 and iPadOS 27 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149034.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Accelerate Framework
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Processing a maliciously crafted image may lead to unexpected
process termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-86882: Peter Malone

Accessibility
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to access sensitive user data
Description: This issue was addressed with improved data protection.
CVE-2026-43664: Stuart Wallace, Ilya Andr (andrd3v), Rosyna Keller of
Totally Not Malicious Software, CJ Vana, David Strnadel, Daniel Febrero,
Asaf Cohen, Gongyu Ma (@Mezone0), Jian Lee (@speedyfriend433)

Accessibility
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to identify what other apps a user has
installed
Description: A privacy issue was addressed with improved handling of
user preferences.
CVE-2026-64761: Stuart Wallace, Sindre Sorhus

Accounts
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: A malicious application may be able to bypass Privacy
preferences
Description: An authorization issue was addressed with improved state
management.
CVE-2026-65404: Arni Hardarson (Neonix Security), Vinay Kumar Rasala
(Xplo8E) from Appknox, Stuart Wallace, 이재영

APFS
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to cause unexpected system termination or
write kernel memory
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-84523: Cem Onat Karagun, an anonymous researcher

App Store
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: A local app may be able to read a persistent account identifier
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-86888: Zhongcheng Li (CK01)

Apple Account
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to use the Sign In With Apple authentication
flow to access the user's Apple Account
Description: An authentication issue was addressed with improved state
management.
CVE-2026-20683: Dem0ns (@天府简易信工作室), Abdelhak Kherroubi, Jasminder Pal
Singh, Lehan Dilusha Jayasingha (Sri Lanka)

Apple Neural Engine
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to cause unexpected system termination
Description: An integer overflow was addressed with improved input
validation.
CVE-2026-65408: tamdao

AppleAVD
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to cause unexpected system termination
Description: A use after free issue was addressed with improved memory
management.
CVE-2026-65407: Franco Belman at Blackwing Intelligence

AppleDouble
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Mounting a disk image with maliciously crafted files may lead to
unexpected system termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-84519: Richard Zana

AppleKeyStore
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to cause unexpected system termination
Description: A use after free issue was addressed with improved memory
management.
CVE-2026-84593: Meta Red Team X - Nik Tsytsarkin, Alexandre Borges

Authentication Services
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to delete credentials stored in Keychain
Description: This issue was addressed by removing the vulnerable code.
CVE-2026-86905: Ilya Andr (andrd3v)

AuthKit
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: A local app may be able to read a persistent account identifier
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-84583: Zhongcheng Li from IES Red Team

AVEVideoEncoder
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to cause unexpected system termination
Description: The issue was addressed with improved checks.
CVE-2026-65410: Calif.io <http://calif.io/> in collaboration with Claude and Anthropic
Research

AVEVideoEncoder
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to cause unexpected system termination
Description: A type confusion issue was addressed with improved memory
handling.
CVE-2026-84616: Peter Malone

AVEVideoEncoder
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: A sandboxed app may be able to execute arbitrary code with
kernel privileges
Description: A race condition was addressed with improved state
management.
CVE-2026-84607: Ruslan Dautov

BackgroundAssets
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to access sensitive user data
Description: A logic issue was addressed with improved validation.
CVE-2026-65406: Ye Zhang (@VAR10CK) of Baidu Security

Baseband
Available for: iPhone 11 and later
Impact: An attacker in radio range may be able to cause unexpected
system termination
Description: An input validation issue was addressed with improved input
validation.
CVE-2026-86885: Tuan D. Hoang, Hazem Issa, and Yongdae Kim @ KAIST
SysSec Lab

Baseband
Available for: iPhone 11 and later
Impact: A remote attacker may be able to cause a denial-of-service
Description: A denial-of-service issue was addressed with improved input
validation.
CVE-2026-86879: Hazem Issa and Yongdae Kim @ SysSec, KAIST

Bluetooth
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: A remote attacker may be able to cause unexpected app
termination or arbitrary code execution
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-65414

Bluetooth
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may gain unauthorized access to Bluetooth
Description: An authorization issue was addressed with improved state
management.
CVE-2026-84560: an anonymous researcher

Camera
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to access sensitive user data
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-86878: Sindre Sorhus, Ilya Andr (andrd3v) of Positive
Technologies, Asaf Cohen

CloudKit
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: A local app may be able to read a persistent account identifier
Description: An information disclosure issue was addressed with improved
state management.
CVE-2026-86895: Stanislav Jelezoglo

CloudKit
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to read device name
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-86893: Heiner Gerdes

copyfile
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An archive may be able to bypass Gatekeeper
Description: A file quarantine bypass was addressed with additional
checks.
CVE-2026-65399: Rishabh Jain (rjcyber) of cyberplanet, Pasquale Scola,
an anonymous researcher

CoreMedia
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Processing a maliciously crafted image may lead to arbitrary
code execution
Description: A memory corruption issue was addressed by removing the
vulnerable code.
CVE-2026-64752: Nik Tsytsarkin

CoreMedia
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: A sandboxed process may be able to circumvent sandbox
restrictions
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-86876: Chris Bailey - Short Circuit

CoreMedia
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Processing a maliciously crafted video file may lead to
unexpected app termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-65344: Siyeong kim

CoreML
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: A sandboxed app may be able to access restricted files
Description: A permissions issue was addressed with improved path
validation.
CVE-2026-84624: AL Najafi, tamdao

CoreMotion
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to access motion data from headphones without
user consent
Description: An authorization issue was addressed with improved
validation.
CVE-2026-43737: Stuart Wallace

CoreText
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Processing web content may lead to a denial-of-service
Description: A null pointer dereference was addressed with improved
input validation.
CVE-2026-65412: Pavan Nallamothu

CoreText
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Processing a maliciously crafted font may result in the
disclosure of process memory
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2026-84596: ret2happy, Meta Product Security

CoreUI
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Processing a maliciously crafted file may lead to unexpected app
termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-84575: Mustafa Calap (@ordinal0, dbg.re)

CoreUI
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to cause a denial of service
Description: A buffer overflow was addressed with improved bounds
checking.
CVE-2026-84489: stratan (@5tratan), Peter Malone

CoreUI
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Processing a maliciously crafted image may lead to unexpected
app termination
Description: A buffer overflow was addressed with improved bounds
checking.
CVE-2026-84571: stratan (@5tratan), Peter Malone

CoreUI
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Processing a maliciously crafted asset catalog may result in
disclosure of process memory
Description: The issue was addressed with improved memory handling.
CVE-2026-43738: Peter Malone

CoreUI
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Processing a maliciously crafted asset catalog may lead to
unexpected process termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-84511: Rahul Raj, stratan (@5tratan)

DeviceCheck
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to read persistent device identifiers
Description: An authorization issue was addressed with improved access
control.
CVE-2026-84612: N.M.Praveen Nawarathne (@zblockrat), James Gill
(@jjtech@infosec.exchange)

Disk Images
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to cause unexpected system termination
Description: The issue was addressed with improved memory handling.
CVE-2026-84552: Tommy DeVoss from Braze Security Team (@thedawgyg),
flower xu, Adriatik Raci, PETOWORKS의 Bugeun Choi (@Bugeun), Peter
Malone, Daisuke Hatakeyama and Ryohei Ueki (@SYZD Research), Hyunwoo Kim
(@v4bel)

exFAT
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Mounting a maliciously crafted volume may lead to unexpected
system termination
Description: A heap buffer overflow was addressed with improved bounds
checking.
CVE-2026-84510: Meta Red Team X - Nik Tsytsarkin, Richard Zana

File Bookmark
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to modify a file it only had permission to
read
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-43785: Junyeong Lee (jylab.github.io <http://jylab.github.io/>), Merrick Hare, Aditya
Kumar, John Nzyuko Uvyu, Narendra Singh (@_3P1C)

file_cmds
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Extracting a maliciously crafted archive may allow an attacker
to write arbitrary files
Description: A path handling issue was addressed with improved
validation.
CVE-2026-84534: Geoffrey Lovelace

Filters
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Processing a maliciously crafted file may lead to unexpected app
termination
Description: A memory corruption issue was addressed with improved input
validation.
CVE-2026-43688: Peter Malone

FontParser
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Processing a maliciously crafted font file may lead to
unexpected app termination
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2026-84524: an anonymous researcher

FontParser
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Processing a maliciously crafted font may result in the
disclosure of process memory
Description: An out-of-bounds read issue was addressed with improved
input validation.
CVE-2026-84597: Nik Tsytsarkin

Foundation
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to cause a denial of service
Description: A type confusion issue was addressed with improved memory
handling.
CVE-2026-65409: Bruce Dang of Calif.io <http://calif.io/> in collaboration with Claude and
Anthropic Research

Graphics
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to cause unexpected system termination
Description: A race condition was addressed with improved state
handling.
CVE-2026-84492: Tommy DeVoss from Braze Security Team (@thedawgyg),
Jiyong Yang

Heimdal
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An attacker in a privileged network position may be able to
modify network traffic
Description: A cryptographic issue was addressed with improved integrity
checks.
CVE-2026-84533: Vishal Patidar, Roman Zabicki

iCloud
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to identify a user across reinstalls
Description: A privacy issue was addressed with improved handling of
identifiers.
CVE-2026-84606: Ilya Andr (andrd3v)

Image Capture
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to access user-sensitive data
Description: A path handling issue was addressed with improved
validation.
CVE-2026-64756: Luke Symons

ImageIO
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Processing a maliciously crafted image may result in disclosure
of process memory
Description: An uninitialized memory issue was addressed with improved
memory initialization.
CVE-2026-84564: Justin O'Leary

ImageIO
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Processing a maliciously crafted image may result in memory
corruption
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-65395: Mateusz Jurczyk of Google Project Zero, Varik Matevosyan

IOKit
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to cause unexpected system termination
Description: A use after free issue was addressed with improved memory
management.
CVE-2026-28969: Mihalis Haatainen, Ashish Kunwar, Ari Hawking, 이재영

IOMobileFrameBuffer
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to cause unexpected system termination or
corrupt kernel memory
Description: An out-of-bounds access issue was addressed with improved
bounds checking.
CVE-2026-65398: Chris Bailey - Short Circuit, Mustafa Calap (@ordinal0,
dbg.re), David Strnadel, Meta Red Team X - Nik Tsytsarkin

IOSurfaceAccelerator
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to leak sensitive kernel state
Description: An information leakage was addressed with additional
validation.
CVE-2026-64760: an anonymous researcher, Seiji Sakurai (@HeapSmasher),
Franco Belman at Blackwing Intelligence

iWork
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: A malicious app may be able to break out of its sandbox
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-65354: Csaba Fitzl (@theevilbit) of Iru

Kernel
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to cause unexpected system termination or
corrupt kernel memory
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-28968: genter0, Svetoslav Stolarov & Aisa Fox, Josh Maine of
Calif.io <http://calif.io/>, Dun

Kernel
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: A local attacker may be able to cause unexpected system
termination or corrupt kernel memory
Description: The issue was addressed with improved memory handling.
CVE-2026-84566: Bernhard Jackiewicz

Kernel
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: A local user may be able to cause unexpected system termination
or read kernel memory
Description: A race condition was addressed with additional validation.
CVE-2026-65415: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd., Ryan Hileman via Xint Code (xint.io <http://xint.io/>)

Kernel
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to cause unexpected system termination or
corrupt kernel memory
Description: A double free issue was addressed with improved memory
management.
CVE-2026-84561: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd., Bhaswanth Chigurupati

Kernel
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to cause unexpected system termination
Description: A race condition was addressed with improved state
handling.
CVE-2026-84630: Tristan Madani (@TristanInSec) from Talence Security
CVE-2026-65360: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.
CVE-2026-65358: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

Kernel
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to cause unexpected system termination
Description: A memory corruption issue was addressed with improved
memory handling.
CVE-2026-65377: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd., Ye Zhang (@VAR10CK) of Baidu Security

Kernel
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app with root privileges may be able to read uninitialized
kernel memory
Description: A memory initialization issue was addressed with improved
memory handling.
CVE-2026-84622: Hiroki Imai (LAC Co., Ltd.)

Kernel
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: A malicious app may be able to gain root privileges
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-43689: Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs

Kernel
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Connecting to a malicious NFS server may disclose kernel memory
Description: The issue was addressed with improved memory handling.
CVE-2026-43687: R4mbb of KRsecurity, Peter Malone

Kernel
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Connecting to a malicious NFS server may lead to kernel memory
corruption
Description: A use-after-free issue was addressed with improved memory
management.
CVE-2026-43686: Peter Malone

Kernel
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to determine kernel memory layout
Description: A memory initialization issue was addressed with improved
memory handling.
CVE-2026-65405: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

Kernel
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to disclose kernel memory
Description: An information disclosure issue was addressed with improved
memory management.
CVE-2026-84530: Vladislav Shevchenko (Positive Technologies)

Kernel
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to cause unexpected system termination
Description: A use after free issue was addressed with improved memory
management.
CVE-2026-84521: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.
CVE-2026-65402: Fábio Luís @scanpt, Richard Zana, Billy Jheng Bing Jhong
and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

Kernel
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: A local user may be able to cause unexpected system termination
or read kernel memory
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2026-65359: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

Kernel
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to cause unexpected system termination or
corrupt kernel memory
Description: A race condition was addressed with improved state
handling.
CVE-2026-84507: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

Kernel
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to disclose kernel memory
Description: An out-of-bounds read was addressed with improved input
validation.
CVE-2026-86903: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

Kernel
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to cause unexpected system termination
Description: A type confusion issue was addressed with improved checks.
CVE-2026-84602: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

libarchive
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Processing a maliciously crafted file may lead to unexpected app
termination
Description: A heap buffer overflow was addressed with improved bounds
checking.
CVE-2026-86870: Kitten Food

Managed Configuration
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to access sensitive user data
Description: A privacy issue was addressed with improved handling of
files.
CVE-2026-86883: Sindre Sorhus, Morris Richman (@morrisinlife), Stuart
Wallace, Tristan Brennan

MediaRemote
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: A sandboxed app may be able to access the System Keychain
Description: An authorization issue was addressed with improved state
management.
CVE-2026-84628: Myeonghun Pak, Nathaniel Oh (@calysteon), Alan Banderas
(@creeper4004)

MobileAccessoryUpdater
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Connecting a malicious accessory may cause unexpected system
termination
Description: A memory corruption issue was addressed with improved input
validation.
CVE-2026-86924: Matthew Zamat

MobileBackup
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to modify protected parts of the file system
Description: A path handling issue was addressed with improved
validation.
CVE-2026-65411: Rodolphe Brunetti (@eisw0lf) of Lupus Nova

MobileBackup
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An attacker with physical access to a trust-paired device may be
able to read and write arbitrary files
Description: A path traversal issue was addressed with improved path
validation.
CVE-2026-84598: Drin Raci of sentry.security

Model I/O
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Opening a maliciously crafted file may lead to unexpected
process termination
Description: A buffer overflow was addressed with improved size
validation.
CVE-2026-84497: Yiğit Can YILMAZ (@yilmazcanyigit)

Music
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state
management.
CVE-2026-84615: Stanislav Jelezoglo

NetworkExtension
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state
management.
CVE-2026-43695: Claudio Bozzato and Francesco Benvenuto of Cisco Talos

NetworkExtension
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to identify what other apps a user has
installed
Description: An information disclosure issue was addressed with improved
state management.
CVE-2026-84626: Sindre Sorhus, Hoffcona of IES Red Team

Photos Storage
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to access sensitive user data
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-84491: an anonymous researcher

Photos Storage
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to fingerprint the user
Description: This issue was addressed with additional entitlement
checks.
CVE-2026-84629: Stanislav Jelezoglo

Power Management
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to fingerprint the device
Description: An authorization issue was addressed with improved state
management.
CVE-2026-84623: Ilya Andr (andrd3v)

RealityKit
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Processing a maliciously crafted file may lead to unexpected app
termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-28966: stratan (@5tratan)

RealityKit
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Opening a maliciously crafted file may cause unexpected process
termination or disclose process memory
Description: An out-of-bounds read issue was addressed with improved
input validation.
CVE-2026-84532: Hongsik Kim (mnur), stratan (@5tratan)

Reminders
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to access sensitive user data
Description: This issue was addressed with improved checks.
CVE-2026-65403: Rahul Raj

Safari
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: A malicious website may be able to determine what apps a user
has installed
Description: This issue was addressed through improved state management.
CVE-2026-84518: Bálint Magyar (balintmagyar.com <http://balintmagyar.com/>)

Safe Browsing
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to access sensitive user data
Description: This issue was addressed with additional entitlement
checks.
CVE-2026-86897: Stuart Wallace

Sandbox
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to bypass network restrictions
Description: A logic issue was addressed with improved validation.
CVE-2026-84551: Issa Sancho

Sandbox Profiles
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to fingerprint the user
Description: A permissions issue was addressed with additional sandbox
restrictions.
CVE-2026-84625: Ilya Andr (andrd3v) of Positive Technologies, CJ Vana

Sandbox Profiles
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to access sensitive user data
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-84603: Gongyu Ma (@Mezone0), CJ Vana, Stanislav Jelezoglo

SceneKit
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Processing a maliciously crafted file may result in disclosure
of process memory
Description: An integer overflow was addressed with improved input
validation.
CVE-2026-84487: stratan (@5tratan), Dhiyanesh Selvaraj (@redroot97),
Peter Malone

SceneKit
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Processing a maliciously crafted 3D model may lead to memory
corruption
Description: The issue was addressed with improved memory handling.
CVE-2026-84632: Peter Malone

SceneKit
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Processing a maliciously crafted 3D model may lead to memory
corruption
Description: An integer overflow was addressed with improved input
validation.
CVE-2026-84620: Peter Malone

SceneKit
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Processing a maliciously crafted 3D model may lead to memory
corruption
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-84546: Narendra Singh (@_3P1C), stratan (@5tratan), Peter
Malone
CVE-2026-84611: Nathaniel Oh (@calysteon)

SceneKit
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Processing a maliciously crafted 3D scene may lead to unexpected
process termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-84526: stratan (@5tratan)

Security
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An attacker with a compromised intermediate certificate
authority may be able to issue certificates with arbitrary extended key
usages
Description: A certificate validation issue was addressed with improved
certificate validation.
CVE-2026-86881: Surya Narayan Kushwaha, Roman Zabicki, John Lussier,
Filip Olszak

Security
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Processing maliciously crafted NTLM input may lead to unexpected
app termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-84531: Meshaal (@unrealmesh)

Shortcuts
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: A malicious shortcut may be able to send messages without user
confirmation
Description: An authorization issue was addressed with improved state
management.
CVE-2026-84600: Owen Pawling (@owenpawling)

Siri
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to access sensitive user data
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-86884: Stanislav Jelezoglo, Gongyu Ma (twitter @Mezone0)

Siri Suggestions
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An attacker with physical access to a locked device may be able
to view sensitive user information
Description: A logic issue was addressed with improved checks.
CVE-2026-86890: Abhay Kailasia (@abhay_kailasia) from Safran Mumbai
India

Software Update
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to modify protected system files
Description: A permissions issue was addressed with improved path
validation.
CVE-2026-84609: YingMuo (@YingMuo) of DEVCORE Research Team

Spotlight
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved access
control.
CVE-2026-84621: Abodi Dawoud, Armend Gashi, Ujjwal Reddy Kalvolu
Sreenivasa Reddy, Johan Wahyudi

SpringBoard
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to cause a denial-of-service
Description: This issue was addressed with additional entitlement
checks.
CVE-2026-86892: Lehan Dilusha Jayasingha

Storage
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to modify protected parts of the file system
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-65348: Jérôme Djouder

Storage
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to access user-sensitive data
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-65345: Seung Je Seong, Ilya Andr (andrd3v) of Positive
Technologies, Jakob Pammer, 이재영

Symptom Framework
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: A malicious application may be able to determine a user's
current location
Description: A privacy issue was addressed with improved private data
redaction for log entries.
CVE-2026-84513: Sindre Sorhus

TCC
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to modify protected system files
Description: A path traversal issue was addressed with improved input
validation.
CVE-2026-86886: Constantin Clerc, Shad J, huami1314 (@huamidev), Huy
Nguyen (@34306) of Calif.io <http://calif.io/>, an anonymous researcher

TCC
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to access sensitive user data
Description: A logging issue was addressed with improved data redaction.
CVE-2026-84527: Zeyang Li&Yuxiang Wang of Chongqing Telecom

Telephony
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An attacker in a privileged network position may be able to
bypass IPSec authentication and intercept network traffic
Description: An authentication issue was addressed with improved state
management.
CVE-2026-65329: Bedran Karakoc, Tobias Funke, Jacopo Clark, Katharina
Kohls of Ruhr University Bochum

Time Zone
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to bypass certain Privacy preferences
Description: A privacy issue was addressed by removing sensitive data.
CVE-2026-86887: an anonymous researcher

Watch App
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to track users across apps and websites
without permission
Description: A privacy issue was addressed with improved state
management.
CVE-2026-86904: Stanislav Jelezoglo

WebKit
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Processing maliciously crafted web content may lead to an
unexpected process termination
Description: A logic issue was addressed with improved state management.
WebKit Bugzilla: 310457
CVE-2026-84635: Souta Sugiyama

WebKit
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Processing maliciously crafted web content may disclose
sensitive user information
Description: A permissions issue was addressed by removing the
vulnerable code.
WebKit Bugzilla: 315121
CVE-2026-64753: Viggo Lekdorf

WebKit
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Opening a maliciously crafted webarchive file may lead to
universal cross-site scripting
Description: A logic issue was addressed with improved state management.
WebKit Bugzilla: 3182711
CVE-2026-86898: Tomi Garcia (archyxsec)

WebKit Canvas
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: A use-after-free issue was addressed with improved memory
management.
WebKit Bugzilla: 313935
CVE-2026-64718: Niels Hofmans, OGINOME Tomohito, an anonymous researcher

Wi-Fi3
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An attacker with physical access to an unlocked device may be
able to view Wi-Fi passwords without authentication
Description: An authentication issue was addressed with improved state
management.
CVE-2026-43674: Yusuf Kelany

Wi-Fi Connectivity
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state
management.
CVE-2026-84636: Jian Lee (@speedyfriend433)

XPC
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th
generation and later, iPad 9th generation and later, and iPad mini 6th
generation and later
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state
management.
CVE-2026-84617: Stuart Wallace

Additional recognition

Accessibility
We would like to acknowledge Abhay Kailasia (@abhay_kailasia) from
Safran Mumbai India for their assistance.

Accounts
We would like to acknowledge Wojciech Regula of SecuRing
(wojciechregula.blog) for their assistance.

Apple Intelligence
We would like to acknowledge an anonymous researcher for their
assistance.

AppleKeyStore
We would like to acknowledge Abdurrahman Nafi, Francisco Knabe, Karol
Mazurek (@Karmaz95) of AFINE, Somair Ansar, YOKI, an anonymous
researcher, 晓娟 谢 for their assistance.

Audio
We would like to acknowledge Dhiyanesh Selvaraj (@redroot97) for their
assistance.

AutoFill
We would like to acknowledge Bistrit Dahal, Oussama Barbar, SalahAldeen
Yousef for their assistance.

AVEVideoEncoder
We would like to acknowledge tamdao for their assistance.

Baseband
We would like to acknowledge Kai Tu, Tianchang Yang, Xiaotian Zhou, Ali
Ranjbar, Abdullah Al Ishtiaq, Tianwei Wu, Yilu Dong, Syed Rafiul Hussain
— SyNSec Lab at Penn State for their assistance.

Bluetooth
We would like to acknowledge David Maynor, Jason Grove, Suresh Sundaram,
Youssef Ahmed Saad, jioundai for their assistance.

BOM
We would like to acknowledge 2ourc3 | Salim Largo for their assistance.

Calendar
We would like to acknowledge Atul Kishor Jaiswal, Dany Assuid, Jacob
Hazak from Zero-Defense Labs, Varik Matevosyan, stratan (@5tratan) for
their assistance.

CipherML
We would like to acknowledge Nils Hanff (@nils1729@chaos.social) of
Hasso Plattner Institute for their assistance.

CloudKit
We would like to acknowledge Ahmed Alwardani, Hikerell (Loadshine Lab)
for their assistance.

Contacts
We would like to acknowledge 이지안 (@speedyfriend433) for their
assistance.

copyfile
We would like to acknowledge Morris Richman (@morrisinlife) and Jian Lee
(@speedyfriend433) for their assistance.

Core Location
We would like to acknowledge CJ Vana for their assistance.

CoreAnimation
We would like to acknowledge Duy Trần (@khanhduytran0) for their
assistance.

CoreAudio
We would like to acknowledge Patrick Saif / x.com/weezerOSINT <http://x.com/weezerOSINT> /
github.com/sai2fast <http://github.com/sai2fast> for their assistance.

CoreBluetooth - LE
We would like to acknowledge Ashmit Sharma & Atul RV, Dun, Maliq
Barnard, Nicholas C. of Onymos Inc. (onymos.com <http://onymos.com/>), Peter Malone, Robert M
for their assistance.

CoreCrypto
We would like to acknowledge Lakshay Sharma for their assistance.

CoreGraphics
We would like to acknowledge Gandalf4a of PKU-Changsha Institute for
Computing and Digital Economy for their assistance.

CoreMedia
We would like to acknowledge Chris Bailey - Short Circuit for their
assistance.

CoreText
We would like to acknowledge Chris Bailey - Short Circuit, Jian Lee
(@speedyfriend433), shobhit srivastav for their assistance.

CoreUI
We would like to acknowledge Peter Malone for their assistance.

DataAccess
We would like to acknowledge Adetayo Adebimpe (Cyboghostginx) for their
assistance.

DiskArbitration
We would like to acknowledge Arni Hardarson (Neonix Security), FRO,
Mustafa Ahmed, Thomas Guillem, 九宫格 of Chongqing Telecom for their
assistance.

FaceTime
We would like to acknowledge Souhaib Naceri for their assistance.

Files
We would like to acknowledge an anonymous researcher for their
assistance.

Foundation
We would like to acknowledge Daniel Luedke, Pavan Nallamothu, Peter
Malone, Tiago "Balgan" Henriques for their assistance.

HFS
We would like to acknowledge an anonymous researcher for their
assistance.

iCloud
We would like to acknowledge 3ndy1(@_3ndy1) and moyu for their
assistance.

iCloud Photo Library
We would like to acknowledge an anonymous researcher for their
assistance.

ImageIO
We would like to acknowledge Muhamad Syaiful, an anonymous researcher,
songbird for their assistance.

IOMobileFrameBuffer
We would like to acknowledge Iain Harkiss, Jian Lee (@speedyfriend433)
for their assistance.

IOSurface
We would like to acknowledge N.M.Praveen Nawarathne (@zblockrat), ธนกฤต
ทัฬหะ for their assistance.

IOSurfaceAccelerator
We would like to acknowledge Chanwit Muenprakoddee (ChemIndy), Franco
Belman at Blackwing Intelligence, Iain Harkiss, an anonymous researcher,
beist, hxr1 for their assistance.

Kernel
We would like to acknowledge Bhaswanth Chigurupati, Billy Jheng Bing
Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Cem
Onat Karagun, DARKNAVY (@DarkNavyOrg), James Duffy (@0x4A616D657344),
Kang Sangkwun, Lyutoon, N.M.Praveen Nawarathne (@zblockrat), Nebula
Security (@nebusecurity), Nicolas Seriot, Peter Malone, Redon Gashi of
Sentry, Robert Tran, Tristan Madani (@TristanInSec) from Talence
Security, Xiang Li from AOSP Lab @Nankai University, an anonymous
researcher for their assistance.

LaunchServices
We would like to acknowledge Rosyna Keller of Totally Not Malicious
Software (paradisefacade.com <http://paradisefacade.com/>) for their assistance.

mDNSResponder
We would like to acknowledge Anton Pakhunov, Franciszek Kalinowski
(striga.ai <http://striga.ai/> / isec.pl), Hannes Weissteiner, Roland Czerny, Simone Franza,
Stefan Gast and Daniel Gruss of Graz University of Technology, and
Johanna Ullrich of the Interdisciplinary Transformation University
(IT:U), Issa Sancho, Jian Zhou, 章鱼哥@aipy (aipyaipy.com <http://aipyaipy.com/>) for their
assistance.

Messages
We would like to acknowledge Pratyush Dutta for their assistance.

Notes
We would like to acknowledge Peter Henri for their assistance.

Notifications
We would like to acknowledge Abhay Kailasia (@abhay_kailasia) from
Safran Mumbai India, Himanshu Bharti @Xpl0itme From Khatima, Jan Rokita
(rokita.me <http://rokita.me/>) for their assistance.

PaperKit
We would like to acknowledge Rahul Raj for their assistance.

Passwords
We would like to acknowledge Catalin Lita of Moralis, Christian
Kohlschütter, David Coomber of Info-Sec.CA, Lukasz Tulikowski at
Software Cloud, Sujay Amin, an anonymous researcher for their
assistance.

ppp
We would like to acknowledge Cem Onat Karagun for their assistance.

Printing
We would like to acknowledge Stuart Wallace for their assistance.

Pro Res
We would like to acknowledge Meta Red Team X - Nik Tsytsarkin for their
assistance.

Quick Look
We would like to acknowledge Peter Malone for their assistance.

RemoteServiceDiscovery
We would like to acknowledge Tristan Madani (@TristanInSec) from Talence
Security, an anonymous researcher for their assistance.

Safari
We would like to acknowledge Dem0ns @天府简易信工作室 for their assistance.

Safari Downloads
We would like to acknowledge Barath Stalin K
(linkedin.com/in/barathstalin <http://linkedin.com/in/barathstalin>), Exell Nakano, Manojkumar Jaganathan
(linkedin.com/in/manojkumar-j-7ba35b202/ <http://linkedin.com/in/manojkumar-j-7ba35b202/>) with HackerBro Technologies,
Praditya Fajar Ramadhan, Zhiyang Zeng (@Wester), shobhit srivastav for
their assistance.

Safari Extensions
We would like to acknowledge Jake Derouin (jakederouin.com <http://jakederouin.com/>) for their
assistance.

Sandbox Profiles
We would like to acknowledge Lachlan Bauerochse for their assistance.

Security
We would like to acknowledge John Lussier, Masahiro Kawada (@kawakatz),
Roman Zabicki for their assistance.

Settings
We would like to acknowledge an anonymous researcher for their
assistance.

Share Sheet
We would like to acknowledge Atul Kishor Jaiswal, Benjamin Hornbeck for
their assistance.

Shortcuts
We would like to acknowledge Csaba Fitzl (@theevilbit) of Iru, GP, Owen
Pawling (@owenpawling) for their assistance.

Status Bar
We would like to acknowledge Andr.Ess, Rosyna Keller of Totally Not
Malicious Software for their assistance.

Terminal
We would like to acknowledge Stuart Thomas for their assistance.

UIKit
We would like to acknowledge Jorge Welch for their assistance.

Virtualization
We would like to acknowledge Ye Zhang (@VAR10CK) of Baidu Security for
their assistance.

VoiceOver
We would like to acknowledge Hariji Vivek Pandey for their assistance.

WebKit
We would like to acknowledge @TristanInSec, Behzad Najjarpour Jabbari
(@_G4ru_), Big Bear, Eddy Tsalolikhin, Henock Habte, Kenneth Hsu, Maher
Azzouzi, Meridian Miftari, OpenAI Codex Security - Amy Burnett, Souta
Sugiyama, Vitaly Simonovich, an anonymous researcher, hamayanhamayan,
lattice, ret2happy, wwwlk for their assistance.

WebKit Canvas
We would like to acknowledge Utkarsh Pal for their assistance.

WebKit JavaScript Bindings
We would like to acknowledge hamayanhamayan for their assistance.

Wi-Fi
We would like to acknowledge E Vestavik (@Dynasty) for their assistance.

Widgets
We would like to acknowledge Vishnu Prasad P G & Akshaya S, an anonymous
researcher for their assistance.

This update is available through iTunes and Software Update on your iOS
device, and will not appear in your computer's Software Update
application, or in the Apple Downloads site. Make sure you have an
Internet connection and have installed the latest version of iTunes from
https://www.apple.com/itunes/

iTunes and Software Update on the device will automatically check
Apple's update server on its weekly schedule. When an update is
detected, it is downloaded and the option to be installed is presented
to the user when the iOS device is docked. We recommend applying the
update immediately if possible. Selecting Don't Install will present the
option the next time you connect your iOS device.

The automatic update process may take up to a week depending on the day
that iTunes or the device checks for updates. You may manually obtain
the update via the Check for Updates button within iTunes, or the
Software Update on your device.

To check that the iPhone, iPod touch, or iPad has been updated:

* Navigate to Settings 
* Select General 
* Select About. 
* The version after applying this update will be "iOS 27 and iPadOS 27".

All information is also posted on the Apple Security Releases
web site: https://support.apple.com/100100.

This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEhjkl+zMLNwFiCT1o4Ifiq8DH7PUFAmqoZvkACgkQ4Ifiq8DH
7PXsrRAAj6Y9oSIa81hShGEgoADpoQG8+vSJXAB3l/ZCmOVRT0VA1fs9ydMSJOId
NRp4zaKNPUcUhyP7p9tsn1mSgGjaELUaSngdyA8LMN6CdX/c9giY0n+Vvhfj4rdE
pndqhgKOpYfepfZ4u1pw2UvukmHJUF58mCy56lFzH/doB4LgqzYNxnohSWBBhpZ/
5xgiC9U9uilFB0Yo9Ffm5RfmCMgSLurT+JugQ1hyKNVT7VNzaZhQ6uG2ul060NIB
jvO9efV5tcTW880TD6Ub2/T1IXRwNHQZmdFDa9v/K9tB4p5JDgAwR1teeOjsaK+w
Fo94/qvUPsFysFyb8nYjekGCIu02uMNCz7pN74B2yCtEYghZM40Kw0kuDh/0utCO
uNWPEh+blY2IVef1xdR4kpjIhUbHKOFs92lm+IVaeqswK+jjjZWC4Iprs1g/6YKS
EpEAFx/6i8c2AOm9bP49kb5zde9uni+yY9M4CZm9cKQJyDktQ35DGc7drDX3KHh3
Ab3bGxitkK/jLaFgV56RJwiyVe85yrEe5XFNkXQJG4Jy154rYx8+B/1yk6+N9cIu
LM2Mg1f4GjRVGYn6iHe4wvLpdlbc6TUvsi93KSlkrgUE++6O0eMf3zy4++U8ccXm
U5PNilsgT24TwlotllfKZnc9WrhLKERGnJR9lguOCMt9vjBM7RE=
=JH6H
-----END PGP SIGNATURE-----
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/

Current thread: