Executive brief
A privacy vulnerability in iOS and iPadOS allows applications to identify users across app reinstalls through persistent identifier handling. This undermines user privacy by enabling apps to track individuals even after they have uninstalled and reinstalled the application, potentially exposing user behavior and preferences across sessions.
Technical details
The vulnerability is a privacy issue stemming from improper handling of identifiers in iOS and iPadOS that enables an app to identify a user across reinstalls. The flaw exists in the identifier management mechanism which fails to adequately isolate or reset persistent identifiers when an application is reinstalled. An attacker needs only to have the target app installed; no special authentication or network access is required beyond standard app permissions. By exploiting this, a malicious app can correlate user identity and behavior across multiple installation cycles, defeating privacy boundaries that users expect when reinstalling software. The issue is fixed in iOS 27, iPadOS 27, and visionOS 27, released on September 14, 2026.
Affected products
- Apple iOS before 27
- Apple iPadOS before 27
- Apple visionOS before 27
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched