PT-2026-91682 · Apple · Ios+8

CVE-2026-86881

·

Published

2026-09-14

·

Updated

2026-09-16

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions iOS versions prior to 26.7 iPadOS versions prior to 26.7 iOS versions prior to 27 iPadOS versions prior to 27 macOS Golden Gate versions prior to 27 macOS Sequoia versions prior to 15.8 macOS Tahoe versions prior to 26.7 tvOS versions prior to 27 visionOS versions prior to 27 watchOS versions prior to 27
Description A certificate validation issue exists where an attacker possessing a compromised intermediate certificate authority could potentially issue certificates with arbitrary extended key usages. Extended key usage is a certificate extension that defines the purpose for which the public key contained in the certificate can be used.
Recommendations Update iOS to version 26.7 or 27 Update iPadOS to version 26.7 or 27 Update macOS Golden Gate to version 27 Update macOS Sequoia to version 15.8 Update macOS Tahoe to version 26.7 Update tvOS to version 27 Update visionOS to version 27 Update watchOS to version 27

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86881

Affected Products

Apple Macos
Ios
Ipados
Macos Golden Gate
Macos Sequoia
Macos Tahoe
Tvos
Visionos
Watchos