An authentication issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1. An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic.
https://www.theregister.com/security/2026/08/18/apple-plugs-image-processing-hole-ripe-for-spyware-abuse/5289031
https://support.apple.com/en-us/148282
Source: Mitre, NVD
Published: 2026-08-17
Updated: 2026-08-18
Base Score: 5.3
Vector: CVSS2#AV:A/AC:H/Au:N/C:C/I:P/A:N
Severity: Medium
Base Score: 5.9
Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
EPSS: 0.00195