STIGQter STIGQter: STIG Summary: Apple iOS/iPadOS 26 Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 13 May 2026:

Apple iOS/iPadOS 26 must be configured to disable Wi-Fi Aware.

DISA Rule

SV-278853r1151257_rule

Vulnerability Number

V-278853

Group Title

PP-MDF-993300

Rule Version

AIOS-26-018300

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Remove Wi-Fi Aware-capable apps on site managed Apple iOS/iPadOS 26 devices.

There are three steps to implementing this control:

1. Train all users to not accept connection requests from nearby devices. This requirement is met by AIOS-26-0011900.

2a. Review all MDM managed apps deployed to site iPhones and iPads. If an app supports Wi-Fi Aware, it must be removed from all site devices.

Note: There is currently no management API/key to disable Wi-Fi Aware on Apple devices.

2b. If a site manages unmanaged apps on site iPhones and iPads, review all unmanaged apps deployed on site iPhones and iPads. If an app supports Wi-Fi Aware, it must be removed from all site devices.

3a. For managed apps being reviewed for approval, the site app vetting process must determine if the app supports Wi-Fi Aware. If Wi-Fi Aware is supported, the app must not be approved for use on site iPhones and iPads.

3b. If a site manages unmanaged apps on site iPhones and iPads, the site app vetting process must determine if the app supports Wi-Fi Aware. If Wi-Fi Aware is supported, the app must not be approved for use on site iPhones and iPads.

Check Contents

Confirm required Wi-Fi Aware procedures have been implemented.

1. Verify required training has been received by site personal that have site managed iPhones and iPads (AIOS-26-0011900).

2. Verify the site reviewed all managed iOS/iPadOS apps installed on site managed iPhones and iPads for Wi-Fi Aware support and removed all apps that support Wi-Fi Aware. Discuss with the ISSO/ISSM. If the site also manages the deployment of unmanaged apps on site managed iPhones and iPads, verify unmanaged apps were also reviewed.

3. Review site app vetting procedures and verify they include review of Wi-Fi Aware capabilities in all apps. Verify apps with Wi-Fi Aware capability are disapproved for use.

If the site has not reviewed current managed apps for Wi-Fi Aware capabilities or did not remove Wi-Fi Aware capable apps, this is a finding.

If the site app vetting procedures do not include a review of Wi-Fi Aware capabilities in all apps or disapprove apps with Wi-Fi Aware capability, this is a finding.

Vulnerability Number

V-278853

Documentable

False

Rule Version

AIOS-26-018300

Severity Override Guidance

Confirm required Wi-Fi Aware procedures have been implemented.

1. Verify required training has been received by site personal that have site managed iPhones and iPads (AIOS-26-0011900).

2. Verify the site reviewed all managed iOS/iPadOS apps installed on site managed iPhones and iPads for Wi-Fi Aware support and removed all apps that support Wi-Fi Aware. Discuss with the ISSO/ISSM. If the site also manages the deployment of unmanaged apps on site managed iPhones and iPads, verify unmanaged apps were also reviewed.

3. Review site app vetting procedures and verify they include review of Wi-Fi Aware capabilities in all apps. Verify apps with Wi-Fi Aware capability are disapproved for use.

If the site has not reviewed current managed apps for Wi-Fi Aware capabilities or did not remove Wi-Fi Aware capable apps, this is a finding.

If the site app vetting procedures do not include a review of Wi-Fi Aware capabilities in all apps or disapprove apps with Wi-Fi Aware capability, this is a finding.

Check Content Reference

M

Target Key

5723