Description
A privacy issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, watchOS 27. An app may be able to track users across apps and websites without permission.
Published: 2026-09-14
Score: n/a
EPSS: n/a
KEV: No
Impact: Privacy Violation
Action: Immediate Patch
AI Analysis

Impact

Apple identified an issue involving improper state management that could allow an application to track a user across multiple apps and websites without the user’s permission. The flaw does not provide code execution or traditional denial‑of‑service capabilities; it simply enables a malicious app to gather and correlate personal activity data, resulting in a privacy breach and potential identity tracking.

Affected Systems

The vulnerability impacts Apple’s mobile platforms: iOS, i available in iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, and watchOS 27. Devices running earlier OS versions are susceptible.

Risk and Exploitability

No EPSS score is available and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, suggesting low exploitation probability at this time. An attacker would need to supply or entice a user to install a malicious application that exploits the state‑management flaw; therefore, the attack vector is likely through the App Store or sideloading. The primary impact remains the unauthorized aggregation of personal data, which could enable targeted phishing or advertising campaigns. Due to the lack of exploitation metrics, the risk is considered moderate but should be addressed promptly because privacy exposure can accumulate over time.

Generated by OpenCVE AI on September 15, 2026 at 08:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest iOS, iPadOS, or watchOS update that includes the 26.7/27 fix
  • Restrict background activity and review app permissions by disabling Background App Refresh for non‑essential apps in Settings → General → Background App Refresh
  • Remove or avoid installing applications that request unnecessary permissions; regularly review installed apps and uninstall any that appear suspicious or have not been updated

Generated by OpenCVE AI on September 15, 2026 at 08:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Cross-Application Tracking via Improper State Management in iOS, iPadOS, and watchOS
Weaknesses CWE-200
CWE-264

Tue, 15 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A privacy issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, watchOS 27. An app may be able to track users across apps and websites without permission.
References

Subscriptions

Apple Ios And Ipados Watchos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-14T20:51:21.722Z

Reserved: 2026-09-08T16:43:41.873Z

Link: CVE-2026-86904

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T21:17:41.247

Modified: 2026-09-14T21:17:41.247

Link: CVE-2026-86904

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T09:00:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-264