Description
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and iPadOS 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to read a persistent device identifier.
Published: 2026-07-27
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A permissions issue in Apple’s operating systems allows an application to read a persistent device identifier, a value that uniquely identifies the device. The vulnerability arises from insufficient permission checks, enabling a malicious or poorly designed app to access data it should not have. This disclosure can be used for profiling or tracking the device owner, but does not provide further system compromise.

Affected Systems

Apple iOS, iPadOS, tvOS, visionOS, and watchOS before version 26.6 are affected. The issue is fixed in iOS 26.6, iPadOS 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity, and the EPSS score of < 1% shows a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need the ability to install or run an application that has been granted incorrect permissions; once this application is present, it can read the persistent identifier, allowing for user tracking. The risk is therefore confined mainly to confidentiality loss of the identifier rather than full system compromise.

Generated by OpenCVE AI on August 4, 2026 at 23:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all Apple devices to iOS 26.6, iPadOS 26.6, tvOS 26.6, visionOS 26.6, or watchOS 26.6 as distributed by Apple.
  • Remove or uninstall applications that request unnecessary access to device identifiers and audit new app installations for excessive permissions.
  • Modify system privacy settings to restrict access to persistent identifiers for third‑party applications and monitor for any unauthorized access attempts.

Generated by OpenCVE AI on August 4, 2026 at 23:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Persistent Device Identifier Disclosure via Permissions Flaw

Tue, 04 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title Persistent Device Identifier Leak via Permission Issue
Weaknesses CWE-284

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Persistent Device Identifier Leak via Permission Issue
Weaknesses CWE-200
CWE-284
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple tvos
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and iPadOS 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to read a persistent device identifier.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Tvos Visionos Watchos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T15:29:01.656Z

Reserved: 2026-07-20T18:10:18.985Z

Link: CVE-2026-64741

cve-icon Vulnrichment

Updated: 2026-07-28T15:28:57.553Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:12.980

Modified: 2026-07-28T18:45:38.337

Link: CVE-2026-64741

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T00:00:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor