CVE-2026-65352
Received Received - Intake

Information Disclosure in Apple iOS and macOS with Private Relay

Vulnerability report for CVE-2026-65352, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: Apple Inc.

Description

An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 26.6.1. A website may be able to determine a user's IP address with Private Relay turned on.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
apple ios 26.6.1
apple ipados 26.6.1
apple macos_tahoe 26.6.2
apple visionos 26.6.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-642 The product stores security-critical state information about its users, or the product itself, in a location that is accessible to unauthorized actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an information disclosure issue where a website may be able to determine a user's IP address even when Private Relay is turned on. Private Relay is designed to hide a user's IP address for privacy, but this flaw allows bypassing that protection.

Impact Analysis

This vulnerability could expose your real IP address to websites, reducing your privacy. It may allow tracking of your location or online activity despite using Private Relay. Attackers could exploit this to target you or infer personal details.

Mitigation Strategies

Update affected systems to the latest versions: iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, or visionOS 26.6.1 as applicable. Disable Private Relay if IP address anonymization is not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-65352. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart