Description
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27, watchOS 27. An app may be able to fingerprint the user.
Published: 2026-09-14
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a permissions issue that was mitigated with additional sandbox restrictions. An application on the device may be able to collect data sufficient to fingerprint the user, potentially exposing sensitive personal information. This flaw does not allow code execution or system compromise, but it increases privacy risk by enabling user tracking.

Affected Systems

Apple devices running iOS, iPadOS, macOS Golden Gate, visionOS, or watchOS with any version older than 27 are affected. The fix is delivered through OS updates version 27 or later.

Risk and Exploitability

EPSS score is < 1%, and the vulnerability is not listed in CISA KEV, indicating a very low likelihood of exploitation yet. Attackers would need to distribute a malicious or compromised app, which can then exploit the sandbox to fingerprint the user. The risk is mostly privacy‑related and depends on the presence of such apps in the user’s environment.

Generated by OpenCVE AI on September 20, 2026 at 20:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest OS release (27 or later) for all affected Apple platforms.
  • Remove or disable any third‑party applications that request broad permissions and have no legitimate need for user data, as these are the primary vectors for fingerprinting.
  • Review and limit app permission settings on your device, especially for location, contacts, and sensor access, to reduce the amount of data an app can gather.

Generated by OpenCVE AI on September 20, 2026 at 20:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Sun, 20 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title Permissions Issue Allowing User Fingerprinting on Apple Devices

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Title Apple Sandbox Permission Flaw Enables App Fingerprinting
Weaknesses CWE-200
CWE-285

Tue, 15 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Title Apple Sandbox Permission Flaw Enables App Fingerprinting
Weaknesses CWE-200
CWE-285

Tue, 15 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27, watchOS 27. An app may be able to fingerprint the user.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Visionos Watchos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T14:09:32.298Z

Reserved: 2026-09-01T21:13:23.287Z

Link: CVE-2026-84625

cve-icon Vulnrichment

Updated: 2026-09-16T14:09:11.675Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:37.523

Modified: 2026-09-23T19:03:16.370

Link: CVE-2026-84625

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T21:00:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor