Skip to finding
important · Mobile — Physical

A physically held, trust-paired iPhone or iPad exposes arbitrary file read and write through MobileBackup.

Affects

Apple iOS and iPadOS, the operating systems on supported iPhones and iPads.

The attacker needs both possession and an existing trust pairing; a path traversal then escapes the backup path and reaches arbitrary files.

Detail and 2 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 20, 2026