Impact
An authorization issue in early iOS and iPadOS releases allows applications to determine device state information for fingerprinting purposes. The flaw arises from improper state management during authorization, enabling an app to access data it should not normally retrieve. The resulting impact is that the device can be uniquely identified, potentially compromising user anonymity and allowing tracking or profiling.
Affected Systems
Apple’s iOS and iPadOS platforms prior to version 26.7 and 27 are affected. The issue is resolved in iOS 26.7, iPadOS 26.7, iOS 27, and iPadOS 27, so any device running earlier editions remains vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity of the vulnerability. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is local, requiring the malicious app to be installed on the device to read device state information and construct a fingerprint.
OpenCVE Enrichment