Description
This issue was addressed with improved data protection. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to read a persistent device identifier.
Published: 2026-07-27
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the operating system’s data protection framework, permitting malicious or compromised applications to retrieve a persistent device identifier. This identifier can be used to track, profile, or link a user across services, thereby exposing sensitive personal information beyond what an application is authorized to access. The vulnerability exemplifies a sensitive information exposure weakness, with the potential to compromise user privacy.

Affected Systems

Apple iOS, iPadOS, macOS (Sequoia 15.7.8, Sonoma 14.8.8, Tahoe 26.6), tvOS, visionOS, and watchOS are affected. The fix has been released in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6. Devices running earlier releases remain vulnerable.

Risk and Exploitability

No public exploit has been reported and the EPSS score is <1%; the vulnerability is not cataloged in CISA KEV. Nonetheless, the risk of data exposure is significant, especially if a malicious or compromised application can be installed. The likely attack vector is the introduction of an app with elevated data‑access privileges, either through the App Store, sideloading, or other means. With no current exploit evidence, the threat appears moderate to high based solely on the potential impact on data confidentiality.

Generated by OpenCVE AI on August 17, 2026 at 23:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest OS updates on all Apple devices (iOS 18.7.10, iOS 26.6, iPadOS 18.7.10, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6).
  • Review installed applications and remove any that appear untrusted or that request unnecessary data‑access permissions.
  • Enforce app restrictions via supervised mode or MDM to allow only approved applications and prevent sideloading.

Generated by OpenCVE AI on August 17, 2026 at 23:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Persistent Device Identifier Exposure in Apple iOS, macOS, tvOS, visionOS, and watchOS

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description This issue was addressed with improved data protection. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data. This issue was addressed with improved data protection. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to read a persistent device identifier.
References

Mon, 03 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Potential Sensitive Data Exposure via Apple OS Data Protection Flaw

Sun, 02 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
Title Potential Sensitive Data Exposure via Apple OS Data Protection Flaw

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description This issue was addressed with improved data protection. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:29:52.572Z

Reserved: 2026-05-01T22:46:27.820Z

Link: CVE-2026-43796

cve-icon Vulnrichment

Updated: 2026-07-28T15:05:05.411Z

cve-icon NVD

Status : Modified

Published: 2026-07-27T21:17:02.893

Modified: 2026-08-17T22:17:11.657

Link: CVE-2026-43796

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T23:45:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor