CVE-2026-28938: IOS vulnerability
Published Sep 14, 2026
·Updated
A privacy issue was addressed by moving sensitive data. This issue is fixed in iOS 26.6 and iPadOS 26.6. An app may be able to fingerprint the user.
Affected Software
2 affected components
iOS=26.6
iPadOS=26.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
iOSto a version that resolves this vulnerability.Fixed in 26.6 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 26.6
Event History
Sep 14, 2026
CVE Published
via MITRE·08:47 PM
Data Sourced
via MITRE·08:47 PM
DescriptionWeakness
Frequently Asked Questions
1
Which devices are affected?
Devices running iOS or iPadOS before version 26.6 are affected. The issue is fixed in iOS 26.6 and iPadOS 26.6.
2
What could a malicious app do?
An app may be able to fingerprint the user, creating a privacy risk. The provided information does not indicate that the app requires any particular permissions or user interaction.