CVE-2026-84606
Apple · iOS, iPadOS, macOS, visionOS
A privacy vulnerability allows unauthorized applications to track and identify users across reinstalls due to improper handling of identifiers in various Apple operating systems.
Executive summary
An unauthenticated privacy flaw in Apple iOS, iPadOS, macOS, and visionOS permits persistent user tracking across application reinstalls, posing a significant threat to user anonymity.
Vulnerability
The vulnerability involves the improper management of device identifiers by the operating system, which can be leveraged by an unauthenticated application to maintain a persistent user identity even after the application is removed and reinstalled.
Business impact
The ability to track users across reinstalls undermines fundamental privacy protections and can be exploited for targeted surveillance or unauthorized profiling of individuals. With a CVSS score of 7.5, this high-severity vulnerability represents a substantial risk to data privacy and regulatory compliance, particularly in environments where user anonymity is required for security or policy reasons.
Remediation
Immediate Action: Update all affected Apple devices to version 27 or later to implement the improved identifier handling.
Proactive Monitoring: Review application inventory and audit third-party software for suspicious behavior related to persistent identifier access.
Compensating Controls: Enforce strict mobile device management (MDM) policies to restrict the installation of untrusted or unauthorized applications that may attempt to exploit device identifiers.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high CVSS severity and the potential for persistent user tracking, organizations should prioritize the deployment of the version 27 updates across all managed Apple hardware. Ensuring that all endpoints are patched is critical to restoring privacy boundaries and mitigating the risk of unauthorized tracking by malicious applications.
More Apple CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 7.5 (3.1)
- Analyst report written