---
id: CVE-2026-43674
title: An authentication issue was addressed with improved state management
summary: >-
  An authentication issue was addressed with improved state management. This
  issue is fixed in iOS 27 and iPadOS 27. An attacker with physical access to an
  unlocked device may be able to view Wi-Fi passwords without authentication.
severity: medium
cvss: 4.6
cvssVector: 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-287
vendor: apple
product: ipados
affected:
  - ipados < 27.0
  - iphone_os < 27.0
patched:
  - ipados 27.0
  - iphone_os 27.0
published: '2026-09-14'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T14:41:20.700'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-43674'
references:
  - url: 'https://support.apple.com/en-us/149034'
    label: product-security@apple.com
tags:
  - nvd
  - cve.org
epss: 0.00215
epssPercentile: 0.12234
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T16:14:07.210479Z'
ingestedAt: '2026-09-14T21:15:17.509Z'
---

## Overview

An authentication issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27. An attacker with physical access to an unlocked device may be able to view Wi-Fi passwords without authentication.

## Affected

- `ipados < 27.0`
- `iphone_os < 27.0`

## Remediation

Upgrade past the affected range:

- `ipados 27.0`
- `iphone_os 27.0`
