Apple iOS: 25 Vulnerabilities Patched in Same-Day Security Update
Apple released a security update addressing 25 vulnerabilities in iOS and iPadOS, impacting privacy, data access, and system stability.

Key findings
- Apple patched 25 vulnerabilities in iOS and iPadOS on September 14, 2026.
- Vulnerabilities include privacy risks, data access issues, and system stability flaws.
- Fixes are available in iOS 27 and iPadOS 27, with some in the 26.7 branch.
- No vulnerabilities were reported as actively exploited in the wild.
- Updates also address issues in macOS, watchOS, tvOS, and visionOS.
On September 14, 2026, Apple Inc. released a significant security update addressing a batch of 25 vulnerabilities across its iOS and iPadOS operating systems, alongside updates for macOS, watchOS, tvOS, and visionOS. The disclosures, all published on the same day, highlight a range of issues including memory corruption, privacy concerns, and potential data access vulnerabilities. These updates are critical for users to maintain the security and integrity of their devices.
Several vulnerabilities fall into categories related to privacy and data access. CVE-2026-86904, for instance, is a privacy issue addressed with improved state management, which could have allowed an app to track users across applications and websites without permission. Similarly, CVE-2026-86895 and CVE-2026-86883, both information disclosure issues, could permit local apps to read persistent account identifiers. CVE-2026-86888 and CVE-2026-86884 also involve permissions issues that could lead to sensitive user data access.
Other vulnerabilities focus on system stability and integrity. CVE-2026-86924, a memory corruption issue, was fixed with improved input validation and could lead to unexpected system termination if a malicious accessory was connected. CVE-2026-86885, an input validation issue, could result in unexpected system termination for an attacker in radio range. Furthermore, CVE-2026-86886, a path traversal issue, could allow an app to modify protected system files.
The batch also includes vulnerabilities that could lead to cross-site scripting and denial-of-service conditions. CVE-2026-86898, a logic issue fixed in Safari and other operating systems, could lead to universal cross-site scripting when opening a maliciously crafted webarchive file. CVE-2026-86892 and CVE-2026-86879, both addressed with entitlement checks or improved input validation respectively, could result in denial-of-service conditions.
Apple addressed these vulnerabilities through various means, including improved input validation, enhanced state management, additional entitlement checks, and removing vulnerable code. The fixes are available in iOS 27 and iPadOS 27, with some also patched in iOS 26.7 and iPadOS 26.7, as well as specific versions of macOS, watchOS, tvOS, and visionOS. For example, CVE-2026-86882, an out-of-bounds write, is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, and several macOS versions.
While the SANS Internet Storm Center noted that none of the vulnerabilities were explicitly labeled as being exploited in the wild, the sheer volume and variety of issues underscore the importance of timely updates. Users are advised to update their devices to the latest available versions to protect against potential exploitation of these flaws. The updates address a wide array of potential attack vectors, from local app privilege escalation to remote denial-of-service.
This coordinated disclosure event on September 14, 2026, emphasizes Apple's ongoing efforts to secure its ecosystem. Users should ensure their iOS and iPadOS devices are updated to at least version 27, or version 26.7 where applicable, to benefit from these crucial security enhancements. Staying informed and applying patches promptly remains the most effective defense against emerging threats.