Description
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to fingerprint the user.
Published: 2026-07-27
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a permissions flaw that allows an application to identify or fingerprint a user across Apple operating systems. Because the system did not enforce sufficient restrictions on the data an app could access, a malicious app could gather identifying information that permits ongoing tracking or profiling of the user. The impact is primarily a privacy violation rather than direct system compromise, but the ability to uniquely identify a device or its user is a significant concern in sensitive environments.

Affected Systems

All recent Apple operating systems are affected, including iOS, iPadOS, macOS (Tahoe), tvOS, visionOS, and watchOS. Apple addressed the issue in the 26.6 releases of each platform; devices running versions older than 26.6 remain vulnerable.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity, while the EPSS score of less than 1 % reflects a low current probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no known large‑scale attacks. Based on the description, an application could read identifying data that should be restricted; however, the CVE does not specify whether elevated privileges or background execution are required, so these conditions are inferred as possible but not confirmed.

Generated by OpenCVE AI on August 4, 2026 at 23:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update all Apple devices to iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, or watchOS 26.6, where the issue is fixed.
  • Enable App Tracking Transparency and deny tracking permissions for any applications that do not require them, limiting the ability of apps to collect unique identifiers.
  • Review privacy settings to restrict access to device identifiers and sensitive data for installed applications, ensuring that only users with explicit permission can access such information.

Generated by OpenCVE AI on August 4, 2026 at 23:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Apple OS Permission Flaw Allows App-Based User Fingerprinting

Tue, 04 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title Permissions flaw enabling app-level user fingerprinting on Apple platforms
Weaknesses CWE-284

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Permissions flaw enabling app-level user fingerprinting on Apple platforms
Weaknesses CWE-200
CWE-284
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to fingerprint the user.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T13:36:54.880Z

Reserved: 2026-05-01T22:46:21.646Z

Link: CVE-2026-43730

cve-icon Vulnrichment

Updated: 2026-07-28T13:36:39.541Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:16:57.587

Modified: 2026-07-28T19:31:51.477

Link: CVE-2026-43730

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T23:45:02Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor