Description
A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8.8. An attacker with physical access may be able to silently persist an Apple Account on an erased device.
Published: 2026-09-14
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Apple Account persistence after device wipe
Action: Patch
AI Analysis

Impact

A correctness issue in macOS allows an attacker with physical access to silently re‑store an Apple Account on a device that has been erased, thereby maintaining access to iCloud services, email, and other personal data that would normally require re‑authentication. The weakness involves improper cleanup or deletion logic that controls the storage of Apple Account state and results in the account lingering after a wipe. This persistence can lead to credential compromise and broader exploitation within the Apple ecosystem.

Affected Systems

Apple macOS devices running any version prior to macOS Sonoma 14.8.8 are affected. The issue is fixed in macOS Sonoma 14.8.8 and later; earlier releases of macOS, including older Sonoma versions, remain vulnerable.

Risk and Exploitability

The flaw requires physical possession of the device and the ability to initiate a device erase, which is why the EPSS score is not available and the vulnerability is not listed in CISA KEV. However, the ability to preserve an Apple Account after a wipe elevates the risk of ongoing data exposure and credential misuse, warranting prompt remediation in any environment where physical device access is possible.

Generated by OpenCVE AI on September 15, 2026 at 10:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all affected macOS devices to macOS Sonoma 14.8.8 or a later patched release.
  • After updating, perform a full factory reset and verify that no Apple Account remains before re‑logging in or using Apple services.
  • Enforce device management policies to restrict physical access, such as mandatory passcodes, restrict device use to authorized personnel, and consider hardware‑based tamper resistance measures.

Generated by OpenCVE AI on September 15, 2026 at 10:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 15 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Title Physical Access Enables Silent Apple Account Persistence on Erased macOS Devices
Weaknesses CWE-284

Mon, 14 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8.8. An attacker with physical access may be able to silently persist an Apple Account on an erased device.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-14T20:48:58.078Z

Reserved: 2026-03-03T16:36:03.969Z

Link: CVE-2026-28836

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T21:17:05.047

Modified: 2026-09-14T21:17:05.047

Link: CVE-2026-28836

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T10:45:09Z

Weaknesses