Junglewise Threat Intelligence

CVE-2026-28938: Apple iOS Accounts Framework user fingerprinting

CVE-2026-28938 · Severity: high · CVSS 7.5 · Published 2026-09-14

Technologies: Apple Iphone Os, Apple iPadOS. Vendors: Apple.

Executive brief

Apple's Accounts Framework, used by apps to manage user credentials and account information on iOS and iPadOS devices, contains a privacy issue that allows apps to fingerprint users through sensitive data exposure. An attacker can exploit this vulnerability by installing a malicious app that collects identifying information about the device user, potentially enabling targeted attacks, unwanted tracking, or identity theft.

Technical details

The vulnerability is a privacy issue in the Accounts Framework component of iOS and iPadOS where sensitive data was inadequately protected, allowing apps to fingerprint users. The root cause is insufficient data protection mechanisms that fail to restrict app access to user-identifying signals. An attacker can exploit this locally by running a malicious app on the device without elevated privileges; no network access or user interaction beyond installation is required. The impact is user fingerprinting and privacy compromise. This issue is fixed in iOS 26.6 and iPadOS 26.6 through improved data protection measures.

Affected products

  • Apple iOS before 26.6
  • Apple iPadOS before 26.6

Timeline

  • 2026-09-14: disclosed: Security advisory published
  • 2026-07-27: patched: iOS 26.6 and iPadOS 26.6 released

References

Related threats