ZeroHour

CVE-2026-86904

mass

Cross-App Tracking Privacy Bypass in Apple iOS, iPadOS, and watchOS

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-86904 is a privacy flaw (CWE-359, exposure of private personal information to an unauthorized actor) in Apple's iOS, iPadOS, and watchOS caused by improper state management, fixed in iOS/iPadOS 26.7, iOS/iPadOS 27, and watchOS 27. An app installed on an unpatched device could abuse the flawed state handling to track a user's activity across other apps and websites without permission, bypassing Apple's user-tracking consent protections. The attacker gains silent cross-app and cross-site user tracking — an integrity impact that earns the issue a high 7.5 CVSS score — rather than code execution or direct data theft from the device. Anyone with an iPhone, iPad, or Apple Watch running a version older than the fixed releases is affected. There is no public proof-of-concept, the flaw is not on CISA's KEV list, and no exploitation in the wild has been reported.

What to do: Update iPhones and iPads to iOS/iPadOS 26.7 or iOS/iPadOS 27, and Apple Watches to watchOS 27, via Settings > General > Software Update (or via MDM for managed fleets). Until patched, review which apps hold tracking permission and scrutinize recently installed third-party apps for unusual data-access behavior. Defenders should verify patch compliance across managed device estates, since no configuration workaround is available for this flaw.

Affected
Apple iOSversions prior to iOS 26.7 (fixed in iOS 26.7 and iOS 27)
Apple iPadOSversions prior to iPadOS 26.7 (fixed in iPadOS 26.7 and iPadOS 27)
Apple watchOSversions prior to watchOS 27 (fixed in watchOS 27)
Estimated exposure
masshundreds of millions to over 1 billion iPhone, iPad, and Apple Watch devices — Apple's active installed base of iPhones, iPads, and Apple Watches exceeds a billion devices globally, and historically a large fraction of that base lags the latest OS release for weeks to months after a patch ships.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A privacy issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, watchOS 27. An app may be able to track users across apps and websites without permission.

Vendors
apple
Products
ipados, iphone os, watchos
Weakness
CWE-359
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.