2026-07-27 20:14CVE-2026-43730apple
PUBLISHED5.2

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to fingerprint the user.

Problem type

  • An app may be able to fingerprint the user

Affected products

Apple

iOS and iPadOS

< 26.6 - AFFECTED

macOS

< 26.6 - AFFECTED

tvOS

< 26.6 - AFFECTED

visionOS

< 26.6 - AFFECTED

watchOS

< 26.6 - AFFECTED

References

GitHub Security Advisories

GHSA-w784-p8qw-f8qf

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6...

https://github.com/advisories/GHSA-w784-p8qw-f8qf

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to fingerprint the user.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-43730
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-43730",
    "assignerOrgId": "286789f9-fbc2-4510-9f9a-43facdede74c",
    "assignerShortName": "apple",
    "dateUpdated": "2026-07-28T13:36:54.880Z",
    "dateReserved": "2026-05-01T22:46:21.646Z",
    "datePublished": "2026-07-27T20:14:12.408Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "286789f9-fbc2-4510-9f9a-43facdede74c",
        "shortName": "apple",
        "dateUpdated": "2026-07-27T20:14:12.408Z"
      },
      "descriptions": [
        {
          "lang": "en",
          "value": "A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to fingerprint the user."
        }
      ],
      "affected": [
        {
          "vendor": "Apple",
          "product": "iOS and iPadOS",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "26.6"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "macOS",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "26.6"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "tvOS",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "26.6"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "visionOS",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "26.6"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "watchOS",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "26.6"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "An app may be able to fingerprint the user"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066"
        },
        {
          "url": "https://support.apple.com/en-us/128067"
        },
        {
          "url": "https://support.apple.com/en-us/128068"
        },
        {
          "url": "https://support.apple.com/en-us/128069"
        },
        {
          "url": "https://support.apple.com/en-us/128070"
        }
      ]
    },
    "adp": [
      {
        "providerMetadata": {
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP",
          "dateUpdated": "2026-07-28T13:36:54.880Z"
        },
        "title": "CISA ADP Vulnrichment",
        "problemTypes": [
          {
            "descriptions": [
              {
                "lang": "en",
                "description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
                "cweId": "CWE-200",
                "type": "CWE"
              }
            ]
          }
        ],
        "metrics": [
          {
            "cvssV3_1": {
              "version": "3.1",
              "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "attackVector": "NETWORK",
              "attackComplexity": "LOW",
              "privilegesRequired": "NONE",
              "userInteraction": "NONE",
              "scope": "UNCHANGED",
              "confidentialityImpact": "HIGH",
              "integrityImpact": "HIGH",
              "availabilityImpact": "HIGH",
              "baseScore": 9.8,
              "baseSeverity": "CRITICAL"
            }
          },
          {}
        ]
      }
    ]
  }
}