Skip to content
appleCVE-2026-86904

A privacy issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, watchOS 27.

High7.5CVE-2026-86904 · Published Sep 14, 2026 · updated Sep 16, 2026

Source advisory

Affected versions

PackageAffectedFixed in
iOS and iPadOS
Vendor
< 26.726.7
< 2727
watchOS
Vendor
< 2727
Details and references

A privacy issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, watchOS 27. An app may be able to track users across apps and websites without permission.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Severity from
no source yet
Weakness
CWE-359

More apple advisories

All
DateAdvisory
Sep 14An authentication issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27.
CVE-2026-20683High7.1fixed in iOS and iPadOS 27, macOS 15.8, macOS 26.7
Sep 14A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8.8.
CVE-2026-28836Medium6.1fixed in macOS 14.8.8
Sep 14A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.6, macOS Tahoe 26.7. An app may bypass Gatekeeper checks.
CVE-2026-28899Medium5.5fixed in macOS 15.8, macOS 26.6, macOS 26.7
Sep 14A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6.
CVE-2026-28933Medium5.5fixed in macOS 14.8.8, macOS 15.7.8, macOS 26.6
Sep 14A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7.
CVE-2026-28934Medium6.5fixed in macOS 15.8, macOS 26.7, macOS 27
Sep 14The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27.
CVE-2026-28935High7.5fixed in iOS and iPadOS 26.6.1, macOS 15.8, macOS 26.6.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.