SEPTEMBER 16, 2026
Live Feed
Back to database
Case File

CVE-2026-86904

HIGH · CVSS 7.5 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

A privacy vulnerability exists in unspecified products that allows apps to potentially track users across different applications and websites without their consent. The issue has been resolved in iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, and watchOS 27. Developers and organizations utilizing these platforms should prioritize updates to mitigate the risk of unauthorized user tracking.

CVE
CVE-2026-86904
Severity
HIGH
CVSS
7.5
EPSS
0.25%

Original NVD Description

A privacy issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, watchOS 27. An app may be able to track users across apps and websites without permission.

Related CVEs

Other vulnerabilities affecting the same vendor(s)