Junglewise Threat Intelligence

CVE-2026-84612: Apple iOS and iPadOS authorization bypass in device identifier access

CVE-2026-84612 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple Tvos, Apple watchOS, Apple Visionos, Apple iPadOS, Apple macOS Tahoe, Apple macOS Golden Gate. Vendors: Apple.

Executive brief

An authorization flaw in iOS and iPadOS allows apps to read persistent device identifiers that should be protected. Device identifiers can be used to track users across apps and services, compromising privacy. Apple has patched this issue across multiple OS versions released in September 2026.

Technical details

This is an authorization bypass vulnerability in iOS and iPadOS access control mechanisms that protect persistent device identifiers. The vulnerability allows a local app to read device identifiers without proper permission checks. An attacker must have the ability to install and run an app on the targeted device (local attack vector). Exploitation enables device fingerprinting and cross-app user tracking. The fix involved improved access control implementation. Patches are available in iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, and corresponding macOS versions released September 14, 2026.

Affected products

  • Apple iOS prior to 26.7 and 27
  • Apple iPadOS prior to 26.7 and 27
  • Apple macOS Golden Gate prior to 27
  • Apple macOS Sequoia prior to 15.8
  • Apple macOS Tahoe prior to 26.7
  • Apple tvOS prior to 27
  • Apple visionOS prior to 27
  • Apple watchOS prior to 27

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched

References

Related threats