This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4. An app may be able to circumvent App Privacy Report logging.
Metrics
Affected Vendors & Products
References
History
Wed, 13 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Bypass of App Privacy Report Logging via Entitlement Check Failure |
Wed, 13 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | App Privacy Report Bypass via Entitlement Check Failure | |
| Weaknesses | CWE-285 |
Wed, 13 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-863 | |
| Metrics |
cvssV3_1
|
Mon, 11 May 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | App Privacy Report Bypass via Entitlement Check Failure | |
| First Time appeared |
Apple
Apple ios And Ipados |
|
| Weaknesses | CWE-285 | |
| Vendors & Products |
Apple
Apple ios And Ipados |
Mon, 11 May 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4. An app may be able to circumvent App Privacy Report logging. | |
| References |
|
Status: PUBLISHED
Assigner: apple
Published:
Updated: 2026-05-13T13:18:13.462Z
Reserved: 2026-03-03T16:36:03.974Z
Link: CVE-2026-28873
Updated: 2026-05-13T13:16:22.943Z
Status : Undergoing Analysis
Published: 2026-05-11T21:18:52.077
Modified: 2026-05-13T14:17:10.680
Link: CVE-2026-28873
No data.