CVE-2026-84625
Apple · iOS, iPadOS, macOS, visionOS, watchOS
A permissions vulnerability in multiple Apple operating systems allows an unauthenticated application to perform unauthorized user fingerprinting due to insufficient sandbox restrictions.
Executive summary
A critical permissions flaw across the Apple ecosystem allows unauthorized applications to fingerprint users, potentially leading to widespread tracking and privacy compromise.
Vulnerability
This issue involves a sandbox restriction failure where an unauthenticated application can bypass security boundaries to access sensitive user identifiers. The vulnerability stems from improper permission management, allowing for persistent user fingerprinting.
Business impact
Successful exploitation of this vulnerability enables malicious applications to track users across sessions and potentially across different services, leading to a significant loss of privacy and data confidentiality. Given the CVSS score of 9.1, this vulnerability is classified as critical, as it allows for large-scale, automated tracking of end-users without requiring any user interaction or elevated privileges.
Remediation
Immediate Action: Update all Apple devices to version 27 or later immediately to apply the necessary sandbox hardening.
Proactive Monitoring: Security teams should monitor application behavior for suspicious background processes or unauthorized access attempts to device identifiers and system metadata.
Compensating Controls: Implement mobile device management policies that restrict the installation of untrusted or third-party applications until devices are fully patched.
Exploitation status
Public Exploit Available: No confirmed public exploit available.
Analyst recommendation
The severity of this vulnerability, combined with its reach across the Apple product line, requires immediate attention from IT administrators and users alike. Organizations should prioritize the deployment of the version 27 update to all managed mobile and desktop devices to ensure that sandbox protections are correctly enforced and user privacy is maintained.
More Apple CVEs all →
History
CVE Brief tracked this CVE 3 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.1 (3.1)
- Analyst report written