---
id: CVE-2026-86887
title: A privacy issue was addressed by removing sensitive data
summary: >-
  A privacy issue was addressed by removing sensitive data. This issue is fixed
  in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS 27. An app may be
  able to bypass certain Privacy preferences.
severity: low
cvss: 3.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
vendor: apple
product: ipados
affected:
  - ipados < 26.7
  - iphone_os < 26.7
  - visionos < 27.0
patched:
  - ipados 26.7
  - iphone_os 26.7
  - visionos 27.0
published: '2026-09-14'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T18:03:25.017'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86887'
references:
  - url: 'https://support.apple.com/en-us/149034'
    label: product-security@apple.com
  - url: 'https://support.apple.com/en-us/149038'
    label: product-security@apple.com
  - url: 'https://support.apple.com/en-us/149041'
    label: product-security@apple.com
tags:
  - nvd
  - cve.org
epss: 0.00122
epssPercentile: 0.02249
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T14:43:41.010788Z'
ingestedAt: '2026-09-14T21:15:17.521Z'
---

## Overview

A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS 27. An app may be able to bypass certain Privacy preferences.

## Affected

- `ipados < 26.7`
- `iphone_os < 26.7`
- `visionos < 27.0`

## Remediation

Upgrade past the affected range:

- `ipados 26.7`
- `iphone_os 26.7`
- `visionos 27.0`
