Executive brief
A security vulnerability in Apple's operating systems could allow a malicious application to uniquely identify and track a user's device without their permission. This 'fingerprinting' can be used to monitor user behavior across different apps and services, compromising personal privacy. The issue affects iPhones, iPads, Apple TVs, Apple Watches, and Vision Pro headsets.
Technical details
A permissions vulnerability exists within the Sandbox Profiles component of multiple Apple operating systems. The flaw allows a locally installed application to bypass intended restrictions to collect device-specific data sufficient for user fingerprinting. This issue was addressed by implementing additional restrictions within the sandbox environment to prevent unauthorized access to identifying information. The vulnerability affects iOS, iPadOS, tvOS, visionOS, and watchOS versions prior to 26.4. An attacker would typically need to entice a user to install a malicious application to exploit this flaw.
Affected products
- Apple iOS Before 26.4
- Apple iPadOS Before 26.4
- Apple tvOS Before 26.4
- Apple visionOS Before 26.4
- Apple watchOS Before 26.4
Timeline
- 2026-03-24: patched: Fixed in iOS 26.4, iPadOS 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4
- 2026-03-25: disclosed