Junglewise Threat Intelligence

CVE-2026-84625: Apple iOS permissions issue allowing user fingerprinting

CVE-2026-84625 · Severity: critical · CVSS 9.1 · Published 2026-09-14

Technologies: Apple macOS, Apple macOS Golden Gate, Apple Iphone Os, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

iOS and iPadOS include sandbox restrictions that prevent apps from gathering information about user behavior and device configuration. A permissions bypass in this sandbox allows malicious apps to fingerprint users—collecting unique identifiers and behavioral patterns—which could enable targeted attacks, account takeover, or privacy violations. Apple patched this in iOS 27 and iPadOS 27 released on September 14, 2026.

Technical details

This vulnerability is a sandbox permissions issue (CWE-276: Incorrect Default Permissions) affecting the iOS and iPadOS app sandbox. The root cause involves insufficient isolation of user-identifying data within the sandbox environment. An app running on the device can bypass intended sandbox restrictions to access fingerprinting-relevant data without explicit user permission. The attack vector is local (requires the app to be installed and run on the device) with no authentication or user interaction required beyond installation. An attacker can fingerprint the user by collecting device identifiers, installed apps, usage patterns, and other telemetry. The vulnerability is patched in iOS 27, iPadOS 27, macOS Golden Gate 27, visionOS 27, and watchOS 27.

Affected products

  • Apple iOS before 27
  • Apple iPadOS before 27
  • Apple macOS Golden Gate before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: patched: iOS 27, iPadOS 27, macOS Golden Gate 27, visionOS 27, and watchOS 27 released with fixes
  • 2026-09-14: disclosed: CVE-2026-84625 published

References

Related threats