Improper authentication in Apple iOS and iPadOS - CVE-2026-65329
Published: August 18, 2026
Vulnerability identifier: #VU143974
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-65329
CWE-ID: CWE-287
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to a state issue in the Telephony service. An remote attacker in the local network can bypass IPSec authentication and intercept network traffic.
Affected software
Apple iOS
iPadOS
iPadOS
How to mitigate CVE-2026-65329
Install updates from vendor's website.
Apple iOS - update to 26.6.1 23G83
iPadOS - update to 26.6.1 23G83
iPadOS - update to 26.6.1 23G83