Apple iPadOS: 25 Vulnerabilities Patched in Same-Day Security Update
Apple patched 25 vulnerabilities in iPadOS on September 14, 2026, addressing privacy, data access, and system stability risks.

Key findings
- Apple patched 25 vulnerabilities in iPadOS disclosed on September 14, 2026.
- Vulnerabilities include privacy risks, data access issues, and system stability flaws.
- Fixes are available in iPadOS 27 and some in the 26.7 branch.
- No vulnerabilities were reported as actively exploited in the wild.
- Updates also address issues in iOS, macOS, watchOS, tvOS, and visionOS.
On September 14, 2026, Apple Inc. released a significant security update addressing a batch of 25 vulnerabilities in its iPadOS operating system, alongside updates for iOS, macOS, watchOS, tvOS, and visionOS. The disclosures, all published on the same day, highlight a range of issues including memory corruption, privacy concerns, and potential data access vulnerabilities. These vulnerabilities, fixed in iPadOS 27 and some in the 26.7 branch, underscore the importance of timely patching for users.
Several vulnerabilities fall into the category of privacy and data access. CVE-2026-86904, an out-of-bounds read, could allow an app to disclose kernel memory. Similarly, CVE-2026-86893 and CVE-2026-86892, both permission issues, could enable an app to read device names or cause a denial-of-service, respectively. CVE-2026-86884, CVE-2026-86878, and CVE-2026-84636 also involve permission issues that could lead to unauthorized access to sensitive user data. Privacy concerns are further highlighted by CVE-2026-86887, which could allow an app to bypass certain privacy preferences, and CVE-2026-86883 and CVE-2026-86878, which could allow an app to access sensitive user data. CVE-2026-86895 and CVE-2026-86888, both information disclosure issues, could allow a local app to read a persistent account identifier.
Memory corruption and system stability were also addressed. CVE-2026-86924, a memory corruption issue, could lead to unexpected system termination when connecting a malicious accessory. CVE-2026-86885, an input validation issue, could cause unexpected system termination for an attacker in radio range. CVE-2026-86886, a path traversal issue, could allow an app to modify protected system files. CVE-2026-86882 and CVE-2026-86869, both out-of-bounds write issues, could lead to unexpected process or app termination, respectively, when processing maliciously crafted images. CVE-2026-86870, a heap buffer overflow, could lead to unexpected app termination when processing a maliciously crafted file. CVE-2026-84632, related to memory handling, could lead to memory corruption when processing a maliciously crafted 3D model. CVE-2026-84630, a race condition, could cause unexpected system termination. CVE-2026-84635, a logic issue, could lead to unexpected process termination when processing maliciously crafted web content.
Other notable vulnerabilities include CVE-2026-86905, which could allow an app to delete credentials stored in Keychain after the vulnerable code was removed. CVE-2026-86898, a logic issue, could lead to universal cross-site scripting when opening a maliciously crafted webarchive file. CVE-2026-86890, a logic issue, could allow an attacker with physical access to a locked device to view sensitive user information. Finally, CVE-2026-86879, a denial-of-service issue, could be exploited by a remote attacker.
The vulnerabilities were fixed in various versions, including iOS 27 and iPadOS 27, as well as earlier versions like iOS 26.7 and iPadOS 26.7. Updates also extend to macOS, watchOS, tvOS, and visionOS. According to related news coverage, none of the vulnerabilities were reported as actively exploited in the wild.
This batch of 25 vulnerabilities highlights ongoing security challenges across Apple's ecosystem. Users are strongly advised to update their devices to the latest available versions to mitigate risks associated with privacy violations, data access, and system stability. The consistent patching across multiple operating systems indicates Apple's commitment to security, but also the persistent nature of complex software vulnerabilities.
CVEs addressed in this batch include CVE-2026-86924, CVE-2026-86905, CVE-2026-86904, CVE-2026-86903, CVE-2026-86898, CVE-2026-86895, CVE-2026-86893, CVE-2026-86892, CVE-2026-86890, CVE-2026-86888, CVE-2026-86887, CVE-2026-86886, CVE-2026-86885, CVE-2026-86884, CVE-2026-86883, CVE-2026-86882, CVE-2026-86881, CVE-2026-86879, CVE-2026-86878, CVE-2026-86870, CVE-2026-86869, CVE-2026-84636, CVE-2026-84635, CVE-2026-84632, and CVE-2026-84630. The fixes are available in iPadOS 27 and iPadOS 26.7. The SANS Internet Storm Center noted that Apple released updates for all its operating systems on this date, patching a total of 261 vulnerabilities. SANS Internet Storm Center Vypr Intelligence