Description
A privacy issue was addressed by moving sensitive data. This issue is fixed in iOS 26.6 and iPadOS 26.6. An app may be able to fingerprint the user.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: User data exposure leading to fingerprinting
Action: Update
AI Analysis

Impact

A privacy issue was addressed by moving sensitive data, allowing a malicious application to potentially fingerprint a user by leveraging the exposed identifiers. This results in unauthorized profiling, violating privacy and potentially enabling targeted attacks.

Affected Systems

Apple iOS and iPadOS systems running versions prior to 26.6 are affected; the fix is implemented in iOS 26.6 and iPadOS 26.6.

Risk and Exploitability

The vulnerability is not listed in CISA KEV and has an EPSS score of < 1%, indicating limited publicly known exploitation. The likely attack vector is an installed application that accesses the relocated sensitive data, inferred from the description. The CVSS score of 7.5 indicates a high‑impact vulnerability, but the low EPSS suggests that exploitation is unlikely at present, resulting in a moderate risk pending further disclosure.

Generated by OpenCVE AI on September 20, 2026 at 21:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the device to iOS 26.6 or iPadOS 26.6 to apply the vendor fix
  • Avoid installing third‑party applications that request excessive sensitive data until the update is installed
  • Review and limit privacy permissions for existing apps via the system settings

Generated by OpenCVE AI on September 20, 2026 at 21:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sun, 20 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Title User Fingerprinting via Sensitive Data Exposure in iOS/iPadOS 26.6

Thu, 17 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 16 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Title App Fingerprinting via Sensitive Data Exposure in iOS and iPadOS
Weaknesses CWE-200 CWE-359
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title App Fingerprinting via Sensitive Data Exposure in iOS and iPadOS
Weaknesses CWE-200

Tue, 15 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Vendors & Products Apple
Apple ios And Ipados

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A privacy issue was addressed by moving sensitive data. This issue is fixed in iOS 26.6 and iPadOS 26.6. An app may be able to fingerprint the user.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T12:30:11.412Z

Reserved: 2026-03-03T16:36:03.989Z

Link: CVE-2026-28938

cve-icon Vulnrichment

Updated: 2026-09-16T12:29:48.307Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:05.710

Modified: 2026-09-17T18:41:26.890

Link: CVE-2026-28938

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T21:30:06Z

Weaknesses
  • CWE-359

    Exposure of Private Personal Information to an Unauthorized Actor