Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-43674

CVE-2026-43674: Apple iPadOS Auth Bypass Vulnerability

CVE-2026-43674 is an authentication bypass flaw in Apple iPadOS that allows attackers with physical access to view Wi-Fi passwords without authentication. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-43674 Overview

CVE-2026-43674 is an authentication weakness affecting Apple iOS and iPadOS. An attacker with physical access to an unlocked device can view stored Wi-Fi passwords without providing authentication. Apple addressed the issue in iOS 27 and iPadOS 27 through improved state management. The flaw maps to CWE-287: Improper Authentication.

Critical Impact

An attacker with brief physical access to an unlocked iPhone or iPad can extract saved Wi-Fi credentials, exposing corporate and personal wireless networks to unauthorized access.

Affected Products

  • Apple iOS versions prior to iOS 27
  • Apple iPadOS versions prior to iPadOS 27
  • iPhone and iPad devices running vulnerable OS builds

Discovery Timeline

  • 2026-09-14 - CVE-2026-43674 published to the National Vulnerability Database (NVD)
  • 2026-09-18 - Last updated in NVD database

Technical Details for CVE-2026-43674

Vulnerability Analysis

The vulnerability resides in an authentication flow that gates access to stored Wi-Fi credentials on iOS and iPadOS. Under normal conditions, viewing a saved Wi-Fi password requires a biometric or passcode challenge. Improper state management allows an attacker holding an unlocked device to bypass that re-authentication prompt. The issue is limited to physical access scenarios and does not enable remote exploitation.

Apple's advisory categorizes the fix as an improvement to state management within the Wi-Fi settings interface. See the Apple security advisory for the vendor's description.

Root Cause

The root cause is an authentication state tracking flaw. The Wi-Fi settings component fails to verify that the user completed a fresh authentication challenge before revealing stored network passwords. When state is not correctly reset between UI transitions, the credential disclosure path becomes reachable without prompting the user.

Attack Vector

Exploitation requires the attacker to have physical possession of an unlocked device. No network access, no user interaction, and no elevated privileges are required beyond having the device in hand. The attacker navigates to the Wi-Fi settings and requests a saved password, at which point the missing authentication check permits disclosure of the plaintext credential. The CVSS vector AV:P/AC:L/PR:N/UI:N reflects the physical-only attack surface with confidentiality-only impact.

No public proof-of-concept code is available for this vulnerability. See the vendor advisory for reproduction context.

Detection Methods for CVE-2026-43674

Indicators of Compromise

  • No file-based or network indicators exist because exploitation occurs entirely through the device UI and leaves no forensic artifacts on the device itself.
  • Unauthorized connections to corporate Wi-Fi networks from unknown devices may be a downstream indicator of leaked credentials.
  • Reports from users of unattended, unlocked iPhones or iPads should be treated as potential exposure events.

Detection Strategies

  • Inventory iOS and iPadOS device fleets via mobile device management (MDM) tooling to identify devices running versions earlier than iOS 27 or iPadOS 27.
  • Monitor wireless authentication logs on enterprise access points for anomalous client MAC addresses connecting with valid corporate credentials.
  • Correlate lost, stolen, or misplaced device reports with subsequent unauthorized Wi-Fi association events on adjacent timelines.

Monitoring Recommendations

  • Enable RADIUS accounting on enterprise Wi-Fi controllers to log every authentication event with client identity.
  • Alert on repeat authentication failures followed by a successful login using the same PSK or credential set.
  • Track MDM compliance dashboards for iOS and iPadOS patch level and flag devices remaining on vulnerable builds.

How to Mitigate CVE-2026-43674

Immediate Actions Required

  • Update all iPhones and iPads to iOS 27 or iPadOS 27 through Settings → General → Software Update or via MDM policy.
  • Enforce short auto-lock timeouts (30 seconds to 1 minute) to reduce the window in which a device is unlocked and unattended.
  • Rotate pre-shared keys for corporate Wi-Fi networks if unpatched devices have been lost, stolen, or left unattended in untrusted environments.

Patch Information

Apple resolved the vulnerability in iOS 27 and iPadOS 27 by improving state management in the affected authentication path. Refer to the Apple support article for iOS 27 and iPadOS 27 security content for the official patch details and installation guidance.

Workarounds

  • Configure MDM policies to require biometric or passcode authentication after short idle intervals.
  • Restrict who can physically handle managed devices through user training and clear acceptable-use policies.
  • Migrate high-value wireless networks from PSK to 802.1X authentication so that a leaked PSK does not grant persistent network access.
  • Where feasible, disable the ability for end users to display saved Wi-Fi passwords via managed configuration profiles.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.