Executive brief
A vulnerability in several Apple operating systems could allow an attacker to track users by identifying their IP address. This affects iPhones, iPads, Macs, and Vision Pro headsets. Exploitation of this flaw compromises user privacy by allowing third parties to monitor a user's location or online activity history. Apple has released software updates to address this issue through improved internal state management.
Technical details
A privacy vulnerability exists in multiple Apple operating systems (iOS, iPadOS, macOS, visionOS) due to improper state management. An attacker can exploit this flaw to track users through their IP address, potentially bypassing intended privacy protections. The root cause was identified as a state management issue that failed to sufficiently mask or rotate network identifiers. Apple addressed the vulnerability in iOS 18.7.9, iOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, and visionOS 26.5 by improving how the system handles state transitions. No user interaction is explicitly required for tracking to occur if the attacker can observe network traffic or interact with the device's network state.
Affected products
- Apple iOS 18.7.9, 26.5
- Apple iPadOS 18.7.9, 26.5
- Apple macOS Sequoia 15.7.7
- Apple macOS Sonoma 14.8.7
- Apple macOS Tahoe 26.5
- Apple visionOS 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched
- 2026-05-11: advisory