CVE-2026-65352
Analyzed Analyzed - Analysis Complete

Information Disclosure in Apple iOS and macOS with Private Relay

Vulnerability report for CVE-2026-65352, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-15

Assigner: Apple Inc.

Description

An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 26.6.1. A website may be able to determine a user's IP address with Private Relay turned on.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-15
Generated
2026-10-05
AI Q&A
2026-09-15
EPSS Evaluated
2026-10-04
NVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
apple macos to 26.6.2 (exc)
apple ipados to 26.6.1 (exc)
apple iphone_os to 26.6.1 (exc)
apple visionos to 26.6.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-642 The product stores security-critical state information about its users, or the product itself, in a location that is accessible to unauthorized actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an information disclosure issue where a website may be able to determine a user's IP address even when Private Relay is turned on. Private Relay is designed to hide a user's IP address for privacy, but this flaw allows bypassing that protection.

Detection Guidance

This vulnerability is specific to Apple's Private Relay feature and may allow a website to determine a user's IP address. Detection would require monitoring network traffic for unusual IP address exposure during Private Relay usage. No direct commands are provided in the context to detect this issue.

Impact Analysis

This vulnerability could expose your real IP address to websites, reducing your privacy. It may allow tracking of your location or online activity despite using Private Relay. Attackers could exploit this to target you or infer personal details.

Compliance Impact

The vulnerability allows a website to determine a user's IP address despite Private Relay being enabled. This could potentially expose user location data, which may conflict with privacy requirements under GDPR and HIPAA. However, the specific impact on compliance depends on how the affected systems are used and configured.

Mitigation Strategies

Update affected systems to the latest versions: iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, or visionOS 26.6.1 as applicable. Disable Private Relay if IP address anonymization is not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-65352. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart