Description
An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27. An app may be able to fingerprint the device.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Device Fingerprinting
Action: Upgrade
AI Analysis

Impact

An authorization issue in early iOS and iPadOS releases allows applications to determine device state information for fingerprinting purposes. The flaw arises from improper state management during authorization, enabling an app to access data it should not normally retrieve. The resulting impact is that the device can be uniquely identified, potentially compromising user anonymity and allowing tracking or profiling.

Affected Systems

Apple’s iOS and iPadOS platforms prior to version 26.7 and 27 are affected. The issue is resolved in iOS 26.7, iPadOS 26.7, iOS 27, and iPadOS 27, so any device running earlier editions remains vulnerable.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity of the vulnerability. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is local, requiring the malicious app to be installed on the device to read device state information and construct a fingerprint.

Generated by OpenCVE AI on September 20, 2026 at 20:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the device to iOS 26.7, iPadOS 26.7, iOS 27, or iPadOS 27 to apply the authorization fix
  • Remove or uninstall third‑party applications that may attempt to obtain device state information until an update is available
  • Enable any available device security settings that limit background state exposure and monitor for anomalous fingerprinting activity

Generated by OpenCVE AI on September 20, 2026 at 20:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Sun, 20 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Device Fingerprinting via Improper State Authorization in iOS and iPadOS

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Device Fingerprinting via Authorization Issue in iOS/iPadOS
Weaknesses CWE-200
CWE-285

Tue, 15 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Title Device Fingerprinting via Authorization Issue in iOS/iPadOS
Weaknesses CWE-200
CWE-285

Tue, 15 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Vendors & Products Apple
Apple ios And Ipados

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27. An app may be able to fingerprint the device.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T15:31:52.078Z

Reserved: 2026-09-01T21:13:23.286Z

Link: CVE-2026-84623

cve-icon Vulnrichment

Updated: 2026-09-17T15:31:05.396Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:37.290

Modified: 2026-09-23T19:06:39.093

Link: CVE-2026-84623

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:45:03Z

Weaknesses