Executive brief
A security issue in Apple's mobile and wearable operating systems could allow sensitive user data to be intercepted because it was being sent over the network without encryption. An attacker on the same network could potentially view private information transmitted by an app. Apple has addressed this by ensuring the data is now sent over secure HTTPS connections.
Technical details
A cleartext transmission of sensitive information vulnerability existed in multiple Apple operating systems. The issue stemmed from the failure to use encrypted transport (HTTPS) when transmitting certain user data over the network. An attacker positioned on the network could intercept this traffic to access sensitive data. Apple addressed the vulnerability by enforcing HTTPS for these transmissions in iOS 26.6, iPadOS 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6.
Affected products
- Apple iOS and iPadOS before 26.6
- Apple tvOS before 26.6
- Apple visionOS before 26.6
- Apple watchOS before 26.6
Timeline
- 2026-07-27: disclosed
- 2026-07-27: advisory
- 2026-07-27: patched