Apple iOS and iPadOS Input Validation Vulnerability Allowing Access to Sensitive User Data

Vulnerability

A vulnerability exists in the Contacts framework of iOS 26.3 and iPadOS 26.3, affecting devices such as iPhone 11 and later, various iPad Pro models, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later. This vulnerability arises from inadequate input validation, which may enable an application to access sensitive user information.

Impact

Exploitation of this vulnerability could allow an application to access sensitive user data, such as contact information.

Added: Mar 25, 2026, 2:38 AM
Updated: Mar 25, 2026, 2:38 AM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
3.3
remediation
7.7
relevance
4.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.