SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84598

HIGH · CVSS 7.5 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A path traversal vulnerability allows an attacker with physical access to a trust-paired iOS or iPadOS device to read and write arbitrary files, potentially compromising sensitive data. Users and organizations relying on affected versions of iOS and iPadOS should prioritize updating to versions 26.7 or 27 to mitigate this risk. This issue underscores the importance of physical security and timely software updates for device integrity.

CVE
CVE-2026-84598
Severity
HIGH
CVSS
7.5
EPSS
0.15%

Original NVD Description

A path traversal issue was addressed with improved path validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27. An attacker with physical access to a trust-paired device may be able to read and write arbitrary files.

Related CVEs

Other vulnerabilities affecting the same vendor(s)