---
id: CVE-2026-86905
title: This issue was addressed by removing the vulnerable code
summary: >-
  This issue was addressed by removing the vulnerable code. This issue is fixed
  in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. An app may be able
  to delete credentials stored in Keychain.
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-284
vendor: apple
product: ipados
affected:
  - ipados < 27.0
  - iphone_os < 27.0
  - macos < 27.0
  - visionos < 27.0
patched:
  - ipados 27.0
  - iphone_os 27.0
  - macos 27.0
  - visionos 27.0
published: '2026-09-14'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T01:02:46.007'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86905'
references:
  - url: 'https://support.apple.com/en-us/149034'
    label: product-security@apple.com
  - url: 'https://support.apple.com/en-us/149035'
    label: product-security@apple.com
  - url: 'https://support.apple.com/en-us/149038'
    label: product-security@apple.com
tags:
  - nvd
  - cve.org
epss: 0.00138
epssPercentile: 0.02631
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T14:30:17.746613Z'
ingestedAt: '2026-09-14T21:15:17.476Z'
---

## Overview

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. An app may be able to delete credentials stored in Keychain.

## Affected

- `ipados < 27.0`
- `iphone_os < 27.0`
- `macos < 27.0`
- `visionos < 27.0`

## Remediation

Upgrade past the affected range:

- `ipados 27.0`
- `iphone_os 27.0`
- `macos 27.0`
- `visionos 27.0`
