Executive brief
An authorization flaw in iOS and iPadOS allows apps to read persistent device identifiers that should be protected. Device identifiers can be used to track users across apps and services, compromising privacy. Apple has patched this issue across multiple OS versions released in September 2026.
Technical details
This is an authorization bypass vulnerability in iOS and iPadOS access control mechanisms that protect persistent device identifiers. The vulnerability allows a local app to read device identifiers without proper permission checks. An attacker must have the ability to install and run an app on the targeted device (local attack vector). Exploitation enables device fingerprinting and cross-app user tracking. The fix involved improved access control implementation. Patches are available in iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, and corresponding macOS versions released September 14, 2026.
Affected products
- Apple iOS prior to 26.7 and 27
- Apple iPadOS prior to 26.7 and 27
- Apple macOS Golden Gate prior to 27
- Apple macOS Sequoia prior to 15.8
- Apple macOS Tahoe prior to 26.7
- Apple tvOS prior to 27
- Apple visionOS prior to 27
- Apple watchOS prior to 27
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched