CVE-2026-28863
medium
CVSS v3
6.5
CVSS v2
—
VIR risk
6.5
Description
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.4 and iPadOS 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to fingerprint the user.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: product-security@apple.com — https://support.apple.com/en-us/126799
Vendor advisory: product-security@apple.com — https://support.apple.com/en-us/126798
Vendor advisory: product-security@apple.com — https://support.apple.com/en-us/126797
Vendor advisory: product-security@apple.com — https://support.apple.com/en-us/126792
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| macos | affected | 26.4 |
References
CWEs
CWE-284
Verify integrity in audit chain (admin only). AS-IS.