ZeroHour

CVE-2026-84606

mass

Cross-Reinstall User Tracking Flaw in Apple iOS, iPadOS, macOS, visionOS

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

A privacy vulnerability in Apple's operating systems stems from improper handling of device and app identifiers (mapped to CWE-287 improper authentication, CWE-330 insufficient randomness, and CWE-359 exposure of personal information). A malicious or overly aggressive app installed on an affected device could abuse these mishandled identifiers to recognize and re-identify the same user even after the app is deleted and reinstalled, defeating the user's expectation that removal resets tracking state. The attacker gains persistent cross-reinstall tracking of individual users, which is scored 7.5 (high) because of its integrity impact on user privacy rather than code execution. All users running iOS, iPadOS, macOS Golden Gate, or visionOS versions prior to 27 are affected, with fixes shipped in iOS 27, iPadOS 27, macOS Golden Gate 27, and visionOS 27. No public proof of concept exists and no exploitation has been observed in the wild.

What to do: Upgrade affected devices to iOS 27, iPadOS 27, macOS Golden Gate 27, or visionOS 27 as soon as they are available, ideally enforced via MDM for managed fleets. No configuration-level workaround reliably prevents the persistent identifier issue, so patching is the primary mitigation. After updating, users who are concerned about historical tracking can delete and reinstall suspicious apps so they receive fresh identifiers under the fixed handling.

Affected
Apple iOSversions prior to iOS 27
Apple iPadOSversions prior to iPadOS 27
Apple macOS Golden Gateversions prior to macOS Golden Gate 27
Apple visionOSversions prior to visionOS 27
Estimated exposure
masslikely on the order of 1 billion+ devices worldwide (Apple's active installed base of iPhones, iPads, Macs, and Vision Pro headsets not yet on version 27) — Apple reports an active installed base of well over 1 billion devices across iOS, iPadOS, macOS, and visionOS, and any device not upgraded to the version-27 releases remains affected by default.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A privacy issue was addressed with improved handling of identifiers. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. An app may be able to identify a user across reinstalls.

Weakness
CWE-287, CWE-330, CWE-359
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.