Executive brief
A privacy vulnerability in Apple's Call History component could allow a malicious application to 'fingerprint' or uniquely identify a user's device. This type of tracking can be used to monitor user behavior across different apps without their consent. Apple has released software updates for iPhone, iPad, and Mac to address this issue by improving how sensitive information is hidden from apps.
Technical details
A privacy vulnerability exists in the Call History component of multiple Apple operating systems. The root cause is the insufficient redaction of sensitive information, which allows a local application to extract data points sufficient for device fingerprinting. This bypasses standard privacy protections intended to prevent persistent tracking of users across different application contexts. The issue was addressed through improved data redaction logic. Affected platforms include iOS, iPadOS, and various versions of macOS. Patches are available in iOS/iPadOS 18.7 and 26, macOS Sequoia 15.7, macOS Sonoma 14.8, and macOS Tahoe 26.
Affected products
- Apple iOS before 18.7, before 26.0
- Apple iPadOS before 18.7, before 26.0
- Apple macOS Sequoia before 15.7
- Apple macOS Sonoma before 14.8
- Apple macOS Tahoe before 26.0
Timeline
- 2025-09-15: disclosed
- 2025-09-15: patched
- 2025-09-15: advisory