CVE-2026-84606
massCross-Reinstall User Tracking Flaw in Apple iOS, iPadOS, macOS, visionOS
A privacy vulnerability in Apple's operating systems stems from improper handling of device and app identifiers (mapped to CWE-287 improper authentication, CWE-330 insufficient randomness, and CWE-359 exposure of personal information). A malicious or overly aggressive app installed on an affected device could abuse these mishandled identifiers to recognize and re-identify the same user even after the app is deleted and reinstalled, defeating the user's expectation that removal resets tracking state. The attacker gains persistent cross-reinstall tracking of individual users, which is scored 7.5 (high) because of its integrity impact on user privacy rather than code execution. All users running iOS, iPadOS, macOS Golden Gate, or visionOS versions prior to 27 are affected, with fixes shipped in iOS 27, iPadOS 27, macOS Golden Gate 27, and visionOS 27. No public proof of concept exists and no exploitation has been observed in the wild.
What to do: Upgrade affected devices to iOS 27, iPadOS 27, macOS Golden Gate 27, or visionOS 27 as soon as they are available, ideally enforced via MDM for managed fleets. No configuration-level workaround reliably prevents the persistent identifier issue, so patching is the primary mitigation. After updating, users who are concerned about historical tracking can delete and reinstall suspicious apps so they receive fresh identifiers under the fixed handling.
| Apple iOS | versions prior to iOS 27 |
| Apple iPadOS | versions prior to iPadOS 27 |
| Apple macOS Golden Gate | versions prior to macOS Golden Gate 27 |
| Apple visionOS | versions prior to visionOS 27 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A privacy issue was addressed with improved handling of identifiers. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. An app may be able to identify a user across reinstalls.
- Weakness
- CWE-287, CWE-330, CWE-359
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.