Executive brief
iOS and iPadOS contain an authorization flaw that allows apps to bypass privacy protections and fingerprint devices through improved state management weaknesses. An attacker could exploit this to identify user devices, potentially enabling targeted tracking or malicious activity. The issue affects millions of iPhone and iPad users running affected iOS/iPadOS versions before the September 2026 security update.
Technical details
This is an authorization bypass vulnerability in iOS and iPadOS caused by improper state management in the system's permission enforcement layer. The vulnerability allows a local app to circumvent authorization checks and access capabilities that should be restricted by privacy settings. Specifically, an app may fingerprint the device by leveraging the state management flaw to determine system configuration or user preferences without proper authorization. The attack requires only a malicious app installed on the device. Apple addressed this issue in iOS 26.7, iPadOS 26.7, iOS 27, and iPadOS 27 by improving state management logic to properly enforce authorization boundaries.
Affected products
- Apple iOS before 26.7 and before 27
- Apple iPadOS before 26.7 and before 27
Timeline
- 2026-09-14: disclosed: CVE-2026-84623 disclosed alongside iOS 27 and iPadOS 27 release
- 2026-09-14: patched: Fixed in iOS 26.7, iPadOS 26.7, iOS 27, and iPadOS 27