CVE-2026-28938: Apple iPadOS

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A privacy issue was addressed by moving sensitive data. This issue is fixed in iOS 26.6 and iPadOS 26.6. An app may be able to fingerprint the user.

Affected products

  • Apple iPadOS: before 26.6 (fixed in 26.6)
  • Apple iPhone OS: before 26.6 (fixed in 26.6)

Published 2026-09-14. Last modified 2026-09-17.