---
id: CVE-2026-86885
title: An input validation issue was addressed with improved input validation
summary: >-
  An input validation issue was addressed with improved input validation. This
  issue is fixed in iOS 27 and iPadOS 27. An attacker in radio range may be able
  to cause unexpected system termination.
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-20
vendor: apple
product: ipados
affected:
  - ipados < 27.0
  - iphone_os < 27.0
patched:
  - ipados 27.0
  - iphone_os 27.0
published: '2026-09-14'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T01:03:50.893'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86885'
references:
  - url: 'https://support.apple.com/en-us/149034'
    label: product-security@apple.com
tags:
  - nvd
  - cve.org
epss: 0.0025
epssPercentile: 0.14512
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T15:27:15.516900Z'
ingestedAt: '2026-09-14T21:15:17.490Z'
---

## Overview

An input validation issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27. An attacker in radio range may be able to cause unexpected system termination.

## Affected

- `ipados < 27.0`
- `iphone_os < 27.0`

## Remediation

Upgrade past the affected range:

- `ipados 27.0`
- `iphone_os 27.0`
