Junglewise Threat Intelligence

CVE-2026-84513: Apple iOS, iPadOS, and macOS location data leakage via log redaction

CVE-2026-84513 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple Tvos, Apple macOS Golden Gate, Apple watchOS, Apple Visionos, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

A privacy flaw in Apple's mobile and desktop operating systems allowed malicious applications to determine a user's current location by exploiting inadequate redaction of location data in system logs. This enables apps to track users' movements without permission, violating privacy expectations and potentially exposing sensitive information about where individuals spend their time.

Technical details

This is a privacy/information disclosure vulnerability in Apple's logging infrastructure where location data was not properly redacted in log entries. The vulnerability allows a malicious application with local access to read system logs and extract unredacted location information that should have been sanitized. The fix involved improved private data redaction mechanisms across iOS, iPadOS, and macOS to ensure location details are properly stripped from log output. Attack requires a locally-installed malicious app with log access; the vulnerability has no network attack vector and was patched in iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27.

Affected products

  • Apple iOS before 26.7 and before 27
  • Apple iPadOS before 26.7 and before 27
  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Fixed in iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27

References

Related threats