Junglewise Threat Intelligence

CVE-2026-64733: Apple multiple operating systems user fingerprinting via improved data protection

CVE-2026-64733 · Severity: info · Published 2026-07-27

Technologies: Apple Tvos, Apple macOS Tahoe, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A privacy vulnerability in Apple operating systems could allow a malicious application to uniquely identify and track a user's device. This 'fingerprinting' can be used to monitor user behavior across different apps without their consent. Apple has released software updates to address this issue by improving data protection mechanisms.

Technical details

A privacy vulnerability existed in multiple Apple operating systems where an application could bypass standard privacy controls to fingerprint the user. The root cause was insufficient data protection for certain device identifiers or attributes. A local application could exploit this to uniquely identify a device, potentially facilitating cross-app tracking. Apple addressed the issue in iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6 by implementing improved data protection logic.

Affected products

  • Apple iOS and iPadOS Before 26.6
  • Apple macOS Tahoe Before 26.6
  • Apple tvOS Before 26.6
  • Apple visionOS Before 26.6
  • Apple watchOS Before 26.6

Timeline

  • 2026-07-27: advisory
  • 2026-07-27: patched

References

Related threats