ZeroHour

CVE-2026-43674

mass

Authentication Bypass Lets Physical Attacker View Wi-Fi Passwords on iOS/iPadOS

CVSS
EPSS
Published
()
Modified
AI analysis

CVE-2026-43674 is an authentication flaw in Apple's iOS and iPadOS caused by improper state management in the handling of sensitive settings. It is triggered when an attacker has physical access to a device that is already unlocked, allowing them to view saved Wi-Fi passwords without passing any additional authentication prompt. Successful abuse reveals stored Wi-Fi network credentials, which an attacker could reuse to join and position themselves on those networks for further attacks. The issue is fixed in iOS 27 and iPadOS 27, meaning devices running earlier releases remain exposed. No public proof-of-concept exists, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported.

What to do: Update iPhones and iPads to iOS 27 or iPadOS 27 as soon as rollout reaches your devices, and prioritize shared or helpdesk-managed devices. Because exploitation requires physical access to an unlocked device, require immediate auto-lock with short timeouts and avoid leaving unlocked devices unattended or handing them to untrusted parties. Administrators should audit managed-device update compliance and treat leaked Wi-Fi credentials as rotatable secrets if devices were exposed.

Affected
Apple iOS (iPhone OS)
Apple iPadOS
Estimated exposure
massPotentially hundreds of millions to over 1 billion iPhone/iPad users (devices not yet updated to iOS/iPadOS 27) — iOS and iPadOS run on more than a billion active Apple devices worldwide, and since the fix ships in a newly released major version, most of the installed base will still be on vulnerable prior releases until adoption progresses.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An authentication issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27. An attacker with physical access to an unlocked device may be able to view Wi-Fi passwords without authentication.

In the news

Apple Updates Everything, (Mon, Sep 14th)

Apple patched a record 261 vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS 27, and other platforms, with none flagged as exploited.

Apple's annual OS update shipped iOS/iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27, and visionOS 27 plus bug-fix releases for the 26 and 15 branches, fixing a record 261 vulnerabilities. Notable issues include multiple kernel flaws allowing root privilege escalation (CVE-2026-43689, CVE-2026-43691, CVE-2026-43698, CVE-2026-43786), remote code execution in CUPS (CVE-2026-43692), kernel memory corruption via malicious NFS servers (CVE-2026-43686, CVE-2026-43687), and WebKit memory corruption from crafted web content (CVE-2026-43715). No vulnerabilities are labeled as actively exploited, and Apple does not assign per-CVE severities. Users report iOS 26.7 being downloaded when iOS 27 is intended, and tools like Little Snitch and BlockBlock need updates before upgrading to macOS 27.