CVE-2026-86886: Use After Free
A path traversal issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, watchOS 27. An app may be able to modify protected system files.
Other sources
Accelerate Framework. An out-of-bounds write issue was addressed with improved bounds checking.
— Apple
Accessibility. A privacy issue was addressed with improved handling of user preferences.
— Apple
Accessibility. This issue was addressed with improved data protection.
— Apple
Accounts. An authorization issue was addressed with improved state management.
— Apple
APFS. An out-of-bounds write issue was addressed with improved bounds checking.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 27 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in iOS 26.7 and iPadOS 26.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in iOS 27 and iPadOS 27 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in watchOS 27 - Remove
Remove
vulnerable code (component not specified)from your environment.This issue is addressed by removing the vulnerable code; ensure the installed update includes the change that removes the vulnerable code.
- Compensating control
If affected, apply the OS update that fixes the issue; otherwise mitigate by restricting access to protected system files (the material notes: “An app may be able to modify protected system files”).
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-86882
- CVE-2026-43664
- CVE-2026-84523
- CVE-2026-86888
- CVE-2026-84586
- CVE-2026-65407
- CVE-2026-65339
- CVE-2026-84583
- CVE-2026-65410
- CVE-2026-84616
- CVE-2026-84607
- CVE-2026-65414
- CVE-2026-84560
- CVE-2026-86895
- CVE-2026-86893
- CVE-2026-65399
- CVE-2026-86891
- CVE-2026-86876
- CVE-2026-43737
- CVE-2026-65412
- CVE-2026-84596
- CVE-2026-84575
- CVE-2026-84571
- CVE-2026-84511
- CVE-2026-84612
- CVE-2026-84524
- CVE-2026-84597
- CVE-2026-65409
- CVE-2026-84492
- CVE-2026-84533
- CVE-2026-84564
- CVE-2026-65347
- CVE-2026-65346
- CVE-2026-64788
- CVE-2026-28969
- CVE-2026-65398
- CVE-2026-64736
- CVE-2026-64760
- CVE-2026-28968
- CVE-2026-65415
- CVE-2026-65343
- CVE-2026-65349
- CVE-2026-84561
- CVE-2026-84630
- CVE-2026-65360
- CVE-2026-65358
- CVE-2026-65377
- CVE-2026-84622
- CVE-2026-43687
- CVE-2026-43686
- CVE-2026-65405
- CVE-2026-84530
- CVE-2026-65402
- CVE-2026-65359
- CVE-2026-84507
- CVE-2026-86903
- CVE-2026-65330
- CVE-2026-28935
- CVE-2026-84602
- CVE-2026-86870
- CVE-2026-84628
- CVE-2026-43695
- CVE-2026-84626
- CVE-2026-84491
- CVE-2026-84629
- CVE-2026-65403
- CVE-2026-84551
- CVE-2026-84625
- CVE-2026-84603
- CVE-2026-84487
- CVE-2026-84632
- CVE-2026-84620
- CVE-2026-84546
- CVE-2026-84611
- CVE-2026-84526
- CVE-2026-86881
- CVE-2026-84600
- CVE-2026-86884
- CVE-2026-84609
- CVE-2026-84513
- CVE-2026-86886
- CVE-2026-84527
- CVE-2026-86904
- CVE-2026-84635
- CVE-2026-65341
- CVE-2026-64753
- CVE-2026-64715
- CVE-2026-64787
- CVE-2026-43794
- CVE-2026-64778
- CVE-2026-65391
- CVE-2026-65390
- CVE-2026-84636
- CVE-2026-64761
- CVE-2026-65404
- CVE-2026-20683
- CVE-2026-65408
- CVE-2026-84519
- CVE-2026-84593
- CVE-2026-86905
- CVE-2026-65406
- CVE-2026-86885
- CVE-2026-86879
- CVE-2026-86878
- CVE-2026-64752
- CVE-2026-65344
- CVE-2026-84624
- CVE-2026-84489
- CVE-2026-43738
- CVE-2026-84552
- CVE-2026-84510
- CVE-2026-43785
- CVE-2026-84534
- CVE-2026-43688
- CVE-2026-84606
- CVE-2026-64756
- CVE-2026-65395
- CVE-2026-65354
- CVE-2026-84566
- CVE-2026-43689
- CVE-2026-84521
- CVE-2026-86883
- CVE-2026-86924
- CVE-2026-65411
- CVE-2026-84598
- CVE-2026-84497
- CVE-2026-84615
- CVE-2026-84623
- CVE-2026-28966
- CVE-2026-84532
- CVE-2026-84518
- CVE-2026-86897
- CVE-2026-84531
- CVE-2026-86890
- CVE-2026-84621
- CVE-2026-86892
- CVE-2026-65348
- CVE-2026-65345
- CVE-2026-65329
- CVE-2026-86887
- CVE-2026-86898
- CVE-2026-64718
- CVE-2026-43674
- CVE-2026-84617
- CVE-2026-43702
- CVE-2026-64758
- CVE-2026-43661
- CVE-2026-86869
- CVE-2026-43743
- CVE-2026-43684
- CVE-2026-43715
Frequently Asked Questions
Which devices should be prioritized for updates?
Prioritize iPhone and iPad devices that have not been updated to iOS 26.7, iPadOS 26.7, iOS 27, or iPadOS 27, as applicable. Apple also lists watchOS 27 as containing the fix.
What level of access is associated with the reported impact?
The reported impact is that an app may be able to modify protected system files. The provided information does not state whether installation of a malicious app, user interaction, or other preconditions are required.