CVE-2026-28938
Apple · iOS and iPadOS
A privacy vulnerability in Apple iOS and iPadOS allows unauthenticated applications to perform user fingerprinting due to improper handling of sensitive data.
Executive summary
A high-severity privacy vulnerability in Apple iOS and iPadOS enables unauthorized tracking of users, necessitating an immediate update to version 26.6 or later.
Vulnerability
The vulnerability involves improper data isolation, which allows an application to fingerprint the user without authentication. This is categorized as a privacy flaw where sensitive information is exposed to unauthorized processes.
Business impact
The ability for an application to fingerprint a user poses a significant risk to individual privacy and organizational compliance. With a CVSS score of 7.5, this high-severity flaw could lead to persistent tracking of users across different applications or services, potentially facilitating targeted phishing or unauthorized profiling.
Remediation
Immediate Action: Update all affected Apple iOS and iPadOS devices to version 26.6 or later to ensure the sensitive data is properly moved and isolated.
Proactive Monitoring: Review mobile device management (MDM) logs for unusual application behavior or unexpected data access patterns originating from third-party applications.
Compensating Controls: Implement strict application vetting policies and utilize mobile security solutions that restrict the permissions of untrusted or non-essential applications.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for unauthorized user tracking, organizations should prioritize the deployment of the 26.6 update across their mobile fleet. Applying this patch is the only definitive way to mitigate the risk of user fingerprinting and maintain data privacy standards.
More Apple CVEs all →
History
CVE Brief tracked this CVE 4 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 7.5 (3.1)
- Analyst report written