CVE-2026-84623

Apple · iOS and iPadOS

An authorization issue in Apple iOS and iPadOS allows unauthorized applications to perform device fingerprinting due to improper state management.

Executive summary

A high-severity authorization vulnerability in Apple iOS and iPadOS could allow malicious applications to fingerprint devices, potentially facilitating tracking or targeted exploitation.

Vulnerability

The vulnerability stems from an authorization flaw related to state management, which can be triggered by an unauthenticated application to gain unauthorized access to device identifiers. This allows for persistent fingerprinting of the device, undermining user privacy and security controls.

Business impact

The ability for an application to fingerprint a device significantly increases the risk of unauthorized tracking, which can be leveraged for targeted social engineering or further exploitation of the device. While the CVSS score of 7.5 reflects a high severity due to the potential for unauthorized information gathering, the impact is primarily focused on the erosion of privacy and the potential for long-term device identification.

Remediation

Immediate Action: Update all affected Apple iOS and iPadOS devices to version 26.7 or 27 immediately to resolve the state management flaw.

Proactive Monitoring: Review application permissions and monitor for unusual network activity or unauthorized attempts to access system-level identifiers by third-party apps.

Compensating Controls: Implement strict mobile device management (MDM) policies to restrict the installation of untrusted or unauthorized applications, which serves as a primary defense against potential fingerprinting attempts.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high severity and the potential for privacy compromise, organizations should prioritize the deployment of iOS and iPadOS updates to all managed devices. Ensuring devices are running the latest patched versions is the most effective method to prevent unauthorized device identification and maintain the integrity of the mobile environment.

More Apple CVEs all →

History

CVE Brief tracked this CVE 4 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 7.5 (3.1)
  4. Analyst report written

Sources