STIGQter STIGQter: STIG Summary: Apple iOS/iPadOS 26 Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 13 May 2026:

Apple iOS/iPadOS 26 must disable "Password AutoFill" in browsers and applications.

DISA Rule

SV-278809r1151176_rule

Vulnerability Number

V-278809

Group Title

PP-MDF-993300

Rule Version

AIOS-26-012700

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Install a configuration profile to disable allow Password AutoFill in the management tool. This is a supervised-only control.

Configuration Profile Key: allowPasswordAutoFill

Check Contents

This is a supervised-only control. If the iPhone or iPad being reviewed is not supervised by the MDM, this control is automatically a finding.

If the iPhone or iPad being reviewed is supervised by the MDM, review configuration settings to confirm "Password AutoFill is not allowed" is disabled.

This check procedure is performed on both the iOS/iPadOS device management tool and the iPhone and iPad.

Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review.

In the iOS/iPadOS management tool, verify "Password AutoFill is not allowed" is unchecked.

On the iPhone/iPad:
1. Open the Settings app.
2. Tap "General".
3. Tap "VPN & Device Management".
4. Tap the Configuration Profile from the iOS management tool containing the restrictions policy.
5. Tap "Restrictions".
6. Verify "Password AutoFill is not allowed" is listed.

If "Password AutoFill is not allowed" is not enabled in the iOS/iPadOS management tool and on the Apple device, this is a finding.

Vulnerability Number

V-278809

Documentable

False

Rule Version

AIOS-26-012700

Severity Override Guidance

This is a supervised-only control. If the iPhone or iPad being reviewed is not supervised by the MDM, this control is automatically a finding.

If the iPhone or iPad being reviewed is supervised by the MDM, review configuration settings to confirm "Password AutoFill is not allowed" is disabled.

This check procedure is performed on both the iOS/iPadOS device management tool and the iPhone and iPad.

Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review.

In the iOS/iPadOS management tool, verify "Password AutoFill is not allowed" is unchecked.

On the iPhone/iPad:
1. Open the Settings app.
2. Tap "General".
3. Tap "VPN & Device Management".
4. Tap the Configuration Profile from the iOS management tool containing the restrictions policy.
5. Tap "Restrictions".
6. Verify "Password AutoFill is not allowed" is listed.

If "Password AutoFill is not allowed" is not enabled in the iOS/iPadOS management tool and on the Apple device, this is a finding.

Check Content Reference

M

Target Key

5723