Executive brief
A vulnerability in Apple's GeoServices component could allow a malicious application installed on a device to access sensitive user data. This affects a wide range of Apple products including iPhones, iPads, and Mac computers. Users should update to the latest software versions to prevent unauthorized data access by third-party apps.
Technical details
An information leakage vulnerability exists in the GeoServices component of multiple Apple operating systems due to insufficient validation. A local attacker with low privileges can exploit this flaw via a malicious application to bypass privacy protections and access sensitive user data. The issue was addressed by implementing additional validation checks. Affected platforms include iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS. Patches are available in versions 18.7.9 and 26.4 for mobile devices and 26.4 for other platforms.
Affected products
- Apple iOS up to 18.7.9, up to 26.4
- Apple iPadOS up to 18.7.9, up to 26.4
- Apple macOS Tahoe up to 26.4
- Apple tvOS up to 26.4
- Apple visionOS up to 26.4
- Apple watchOS up to 26.4
Timeline
- 2026-03-24: disclosed: Initial disclosure by Apple
- 2026-03-24: patched: Fixes released in iOS 26.4 and other platforms
- 2026-03-25: advisory: NVD publication date