Junglewise Threat Intelligence

CVE-2026-84629: Apple iOS and iPadOS user fingerprinting vulnerability

CVE-2026-84629 · Severity: high · CVSS 7.5 · Published 2026-09-14

Technologies: Apple Tvos, Apple Iphone Os, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

An app on iOS and iPadOS devices can use entitlement loopholes to fingerprint users and identify specific information about their device or account. This could enable targeted attacks, tracking of individuals, or account takeover when combined with other vulnerabilities. The issue has been patched in iOS 27 and iPadOS 27.

Technical details

The vulnerability is an entitlement bypass issue in iOS and iPadOS where an app can collect information that identifies a specific user or device. The flaw stems from insufficient entitlement checks in a system component that handles user identification or device characteristics. An attacker must develop a malicious app that exploits the missing validation to fingerprint users. The attack is local and does not require user interaction beyond app installation. The fix involved implementing additional entitlement checks to restrict access to identifying information.

Affected products

  • Apple iOS prior to 27
  • Apple iPadOS prior to 27

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: iOS 27 and iPadOS 27 released

References

Related threats