VDB

CVE-2026-28938

CVE-2026-28938 PUBLISHED CVSS 7.5 HIGH

Reported by apple · Published September 14, 2026

A privacy issue was addressed by moving sensitive data. This issue is fixed in iOS 26.6 and iPadOS 26.6. An app may be able to fingerprint the user.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
AppleiOS and iPadOS0
AppleiOS and iPadOS0, 0

Timeline

  • Sep 14, 2026 CVE Published
  • Sep 15, 2026 EPSS Score
  • Sep 15, 2026 Coalition ESS Score
  • Sep 17, 2026 EPSS Score
  • Sep 17, 2026 CVE Updated
  • Sep 18, 2026 EPSS Score
  • Sep 24, 2026 EPSS Score
  • Sep 26, 2026 EPSS Score
  • Sep 30, 2026 EPSS Score
  • Oct 2, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›