Junglewise Threat Intelligence

CVE-2026-86904: Apple iOS iPadOS watchOS cross-app tracking privacy issue

CVE-2026-86904 · Severity: high · CVSS 7.5 · Published 2026-09-14

Technologies: Apple Iphone Os, Apple watchOS, Apple iPadOS. Vendors: Apple.

Executive brief

Apple's iOS, iPadOS, and watchOS operating systems contained a privacy vulnerability that allowed apps to track user activity across different applications and websites without authorization. This undermines user privacy settings and could enable unauthorized profiling, targeting, and surveillance of user behavior across the platform. The issue has been patched in iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, and watchOS 27.

Technical details

A state management flaw in the privacy framework allowed third-party applications to bypass privacy protections and track users across application and web boundaries without explicit permission. The vulnerability was addressed through improved state management in the privacy subsystem. The attack requires only that an app be installed on the device; no network access or user interaction beyond normal app usage is needed. An attacker with a malicious app could correlate user behavior across different apps and websites, creating detailed usage profiles. Apple released patches on September 14, 2026.

Affected products

  • Apple iOS before 26.7, before 27
  • Apple iPadOS before 26.7, before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: patched: Fixed in iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, and watchOS 27
  • 2026-09-14: disclosed: CVE-2026-86904 published

References

Related threats