Executive brief
A security issue in Apple's mobile and wearable operating systems could allow a malicious application to access a persistent device identifier. This type of identifier can be used to track a user's device across different apps and services without their consent, impacting user privacy. Apple has released updates for iPhone, iPad, Apple Watch, Apple TV, and Vision Pro to restrict access to this information.
Technical details
A permissions vulnerability existed in multiple Apple operating systems where insufficient restrictions allowed third-party applications to access a persistent device identifier. This identifier is typically restricted to prevent cross-app tracking and maintain user privacy. The issue was addressed by implementing additional permission restrictions in the affected components. An attacker would need to have a malicious app running locally on the device to exploit this. The fix is available in iOS 26.6, iPadOS 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6.
Affected products
- Apple iOS and iPadOS Before 26.6
- Apple tvOS Before 26.6
- Apple visionOS Before 26.6
- Apple watchOS Before 26.6
Timeline
- 2026-07-27: advisory
- 2026-07-27: disclosed
- 2026-07-27: patched