
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-86924 is a memory corruption vulnerability in Apple's MobileAccessoryUpdater component that can be triggered by connecting a malicious physical accessory to an affected device. The vulnerability was disclosed and patched on September 14, 2026, affecting iOS and iPadOS versions prior to 26.7 and 27, as well as macOS Tahoe prior to 26.7 and macOS Golden Gate prior to 27. The flaw was discovered by researcher Matthew Zamat. A formal CVSS score has not yet been published (EUVD base score listed as 0.0 pending full analysis), though Feedly estimates the severity as HIGH (Apple iOS 26.7 Advisory, Apple macOS Tahoe Advisory, Feedly).
The vulnerability is classified as a memory corruption issue (CWE-119/CWE-787) within the MobileAccessoryUpdater component, which handles firmware updates and communication for connected accessories. Apple addressed the flaw with improved input validation, indicating that malformed or malicious data supplied by a connected accessory was not properly sanitized before being processed, leading to memory corruption. Exploitation requires physical access to the target device — an attacker must connect a specially crafted malicious accessory (e.g., via Lightning or USB-C) to trigger the vulnerability. No public proof-of-concept code or detailed technical write-up has been published as of the disclosure date (Apple iOS 26.7 Advisory, Apple macOS Tahoe Advisory).
Successful exploitation causes unexpected system termination (i.e., a forced device crash or restart), constituting a Denial of Service (DoS) impact on the affected device. Because physical access is required to connect the malicious accessory, the attack surface is limited to scenarios where an adversary has direct, hands-on access to the target iPhone, iPad, or Mac. There is no evidence that this vulnerability enables code execution, data exfiltration, or privilege escalation beyond the crash condition (Apple iOS 26.7 Advisory, Apple macOS Tahoe Advisory, Feedly).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date. The EPSS score is 0.0, reflecting a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Physical access is a significant barrier to exploitation, substantially limiting the realistic threat actor pool to those with direct device access (Feedly, Apple iOS 26.7 Advisory).
MobileAccessoryUpdater or related accessory daemon processes around the time an accessory was connected.MobileAccessoryUpdater process.Apple has released patches addressing this vulnerability in iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, macOS Tahoe 26.7, and macOS Golden Gate 27, all released on September 14, 2026. Users should update their devices to these versions or later as the primary remediation. As a precautionary workaround, users should avoid connecting unknown, untrusted, or unverified accessories to their Apple devices until the update is applied (Apple iOS 26.7 Advisory, Apple iOS 27 Advisory, Apple macOS Tahoe Advisory, Apple macOS Golden Gate Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."