Executive brief
A vulnerability in Apple's mobile operating systems could allow a malicious application to bypass privacy logging features. Specifically, an app could perform actions without them being recorded in the App Privacy Report, which is designed to give users visibility into how apps access their data and sensors. This undermines a user's ability to monitor and control their personal information on their iPhone or iPad.
Technical details
A privacy vulnerability exists in iOS and iPadOS where an application can bypass the App Privacy Report logging mechanism. The issue stems from insufficient entitlement checks when an app accesses certain system resources or data. By exploiting this flaw, a local application can hide its activity from the user-facing privacy audit logs. Apple addressed this issue by implementing additional entitlement checks to ensure all relevant activities are correctly authorized and logged. The fix is available in iOS/iPadOS 18.7.9 and iOS/iPadOS 26.4.
Affected products
- Apple iOS Before 18.7.9, before 26.4
- Apple iPadOS Before 18.7.9, before 26.4
Timeline
- 2026-03-24: patched: Initial patch released in iOS 26.4
- 2026-05-11: advisory: Advisory published for iOS 18.7.9 and 26.4