This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4. An app may be able to circumvent App Privacy Report logging.
Metrics
Affected Vendors & Products
References
History
Mon, 11 May 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | App Privacy Report Bypass via Entitlement Check Failure | |
| First Time appeared |
Apple
Apple ios And Ipados |
|
| Weaknesses | CWE-285 | |
| Vendors & Products |
Apple
Apple ios And Ipados |
Mon, 11 May 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4. An app may be able to circumvent App Privacy Report logging. | |
| References |
|
Status: PUBLISHED
Assigner: apple
Published:
Updated: 2026-05-11T20:08:38.388Z
Reserved: 2026-03-03T16:36:03.974Z
Link: CVE-2026-28873
No data.
Status : Received
Published: 2026-05-11T21:18:52.077
Modified: 2026-05-11T21:18:52.077
Link: CVE-2026-28873
No data.
OpenCVE Enrichment
Updated: 2026-05-11T21:45:36Z