Junglewise Threat Intelligence

CVE-2026-43730: Apple multiple operating systems user fingerprinting via permissions issue

CVE-2026-43730 · Severity: info · Published 2026-07-27

Technologies: Apple Tvos, Apple macOS, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A security issue in Apple operating systems could allow a malicious application to track or "fingerprint" a user without their permission. This type of tracking can be used to identify individuals across different apps and services, compromising user privacy. Apple has released updates for iPhone, iPad, Mac, Apple TV, and Apple Watch to restrict the data accessible to apps and prevent this behavior.

Technical details

A permissions vulnerability exists across Apple's ecosystem (iOS, iPadOS, macOS, tvOS, visionOS, and watchOS) where insufficient restrictions allowed applications to access enough system information to fingerprint the user. Fingerprinting typically involves collecting unique hardware or software configurations to track users without using standard identifiers. The vulnerability was addressed by implementing stricter permission checks and additional restrictions on data access. An attacker would need to have a malicious or unauthorized app running on the target device to exploit this. Fixes are available in version 26.6 of the respective operating systems.

Affected products

  • Apple iOS and iPadOS < 26.6
  • Apple macOS Tahoe < 26.6
  • Apple tvOS < 26.6
  • Apple visionOS < 26.6
  • Apple watchOS < 26.6

Timeline

  • 2026-07-27: disclosed
  • 2026-07-27: patched

References

Related threats