CVE-2026-86904
massCross-App Tracking Privacy Bypass in Apple iOS, iPadOS, and watchOS
CVE-2026-86904 is a privacy flaw (CWE-359, exposure of private personal information to an unauthorized actor) in Apple's iOS, iPadOS, and watchOS caused by improper state management, fixed in iOS/iPadOS 26.7, iOS/iPadOS 27, and watchOS 27. An app installed on an unpatched device could abuse the flawed state handling to track a user's activity across other apps and websites without permission, bypassing Apple's user-tracking consent protections. The attacker gains silent cross-app and cross-site user tracking — an integrity impact that earns the issue a high 7.5 CVSS score — rather than code execution or direct data theft from the device. Anyone with an iPhone, iPad, or Apple Watch running a version older than the fixed releases is affected. There is no public proof-of-concept, the flaw is not on CISA's KEV list, and no exploitation in the wild has been reported.
What to do: Update iPhones and iPads to iOS/iPadOS 26.7 or iOS/iPadOS 27, and Apple Watches to watchOS 27, via Settings > General > Software Update (or via MDM for managed fleets). Until patched, review which apps hold tracking permission and scrutinize recently installed third-party apps for unusual data-access behavior. Defenders should verify patch compliance across managed device estates, since no configuration workaround is available for this flaw.
| Apple iOS | versions prior to iOS 26.7 (fixed in iOS 26.7 and iOS 27) |
| Apple iPadOS | versions prior to iPadOS 26.7 (fixed in iPadOS 26.7 and iPadOS 27) |
| Apple watchOS | versions prior to watchOS 27 (fixed in watchOS 27) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A privacy issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, watchOS 27. An app may be able to track users across apps and websites without permission.
- Vendors
- apple
- Products
- ipados, iphone os, watchos
- Weakness
- CWE-359
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.