CVE-2026-86878: Use After Free
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27. An app may be able to access sensitive user data.
Other sources
Accelerate Framework. An out-of-bounds write issue was addressed with improved bounds checking.
— Apple
Accessibility. A privacy issue was addressed with improved handling of user preferences.
— Apple
Accessibility. This issue was addressed with improved data protection.
— Apple
Accounts. An authorization issue was addressed with improved state management.
— Apple
APFS. An out-of-bounds write issue was addressed with improved bounds checking.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 27 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in iOS 27 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in iPadOS 27
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-86882
- CVE-2026-43664
- CVE-2026-64761
- CVE-2026-65404
- CVE-2026-84523
- CVE-2026-86888
- CVE-2026-20683
- CVE-2026-65408
- CVE-2026-65407
- CVE-2026-84519
- CVE-2026-84593
- CVE-2026-86905
- CVE-2026-84583
- CVE-2026-65410
- CVE-2026-84616
- CVE-2026-84607
- CVE-2026-65406
- CVE-2026-86885
- CVE-2026-86879
- CVE-2026-65414
- CVE-2026-84560
- CVE-2026-86878
- CVE-2026-86895
- CVE-2026-86893
- CVE-2026-65399
- CVE-2026-64752
- CVE-2026-86876
- CVE-2026-65344
- CVE-2026-84624
- CVE-2026-43737
- CVE-2026-65412
- CVE-2026-84596
- CVE-2026-84575
- CVE-2026-84489
- CVE-2026-84571
- CVE-2026-43738
- CVE-2026-84511
- CVE-2026-84612
- CVE-2026-84552
- CVE-2026-84510
- CVE-2026-43785
- CVE-2026-84534
- CVE-2026-43688
- CVE-2026-84524
- CVE-2026-84597
- CVE-2026-65409
- CVE-2026-84492
- CVE-2026-84533
- CVE-2026-84606
- CVE-2026-64756
- CVE-2026-84564
- CVE-2026-65395
- CVE-2026-28969
- CVE-2026-65398
- CVE-2026-64760
- CVE-2026-65354
- CVE-2026-28968
- CVE-2026-84566
- CVE-2026-65415
- CVE-2026-84561
- CVE-2026-84630
- CVE-2026-65360
- CVE-2026-65358
- CVE-2026-65377
- CVE-2026-84622
- CVE-2026-43689
- CVE-2026-43687
- CVE-2026-43686
- CVE-2026-65405
- CVE-2026-84530
- CVE-2026-84521
- CVE-2026-65402
- CVE-2026-65359
- CVE-2026-84507
- CVE-2026-86903
- CVE-2026-84602
- CVE-2026-86870
- CVE-2026-86883
- CVE-2026-84628
- CVE-2026-86924
- CVE-2026-65411
- CVE-2026-84598
- CVE-2026-84497
- CVE-2026-84615
- CVE-2026-43695
- CVE-2026-84626
- CVE-2026-84491
- CVE-2026-84629
- CVE-2026-84623
- CVE-2026-28966
- CVE-2026-84532
- CVE-2026-65403
- CVE-2026-84518
- CVE-2026-86897
- CVE-2026-84551
- CVE-2026-84625
- CVE-2026-84603
- CVE-2026-84487
- CVE-2026-84632
- CVE-2026-84620
- CVE-2026-84546
- CVE-2026-84611
- CVE-2026-84526
- CVE-2026-86881
- CVE-2026-84531
- CVE-2026-84600
- CVE-2026-86884
- CVE-2026-86890
- CVE-2026-84609
- CVE-2026-84621
- CVE-2026-86892
- CVE-2026-65348
- CVE-2026-65345
- CVE-2026-84513
- CVE-2026-86886
- CVE-2026-84527
- CVE-2026-65329
- CVE-2026-86887
- CVE-2026-86904
- CVE-2026-84635
- CVE-2026-64753
- CVE-2026-86898
- CVE-2026-64718
- CVE-2026-43674
- CVE-2026-84636
- CVE-2026-84617
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates local access is required. The attacker does not need privileges, but user interaction is required.
What is the expected security impact?
The CVSS vector rates confidentiality impact as high, with no indicated integrity or availability impact.
Which Apple operating systems are listed as affected?
The affected software list includes Apple iPadOS, Apple iOS, and Apple iPhone OS.