VDB
CVE-2026-28938
CVE-2026-28938
PUBLISHED
CVSS 7.5 HIGH
Reported by apple · Published September 14, 2026
A privacy issue was addressed by moving sensitive data. This issue is fixed in iOS 26.6 and iPadOS 26.6. An app may be able to fingerprint the user.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | iOS and iPadOS | 0 |
| Apple | iOS and iPadOS | 0, 0 |
Timeline
- Sep 14, 2026 CVE Published
- Sep 15, 2026 EPSS Score
- Sep 15, 2026 Coalition ESS Score
- Sep 17, 2026 EPSS Score
- Sep 17, 2026 CVE Updated
- Sep 18, 2026 EPSS Score
- Sep 24, 2026 EPSS Score
- Sep 26, 2026 EPSS Score
- Sep 30, 2026 EPSS Score
- Oct 2, 2026 EPSS Score