Impact
A correctness issue in macOS allows an attacker with physical access to silently recover an Apple Account after a device has been erased. The vulnerability stems from inadequate cleanup of account state during a wipe, enabling the account to remain cached and automatically restored. This allows the attacker to access iCloud services, email, and other personal data that would normally require re‑authentication, potentially exposing credentials and sensitive information.
Affected Systems
Apple macOS devices running any version prior to macOS Sonoma 14.8.8 are affected. The issue is addressed in macOS Sonoma 14.8.8; earlier releases, including older versions of Sonoma, remain vulnerable.
Risk and Exploitability
The flaw requires physical possession of the device and the ability to initiate a device erase, which explains the EPSS score of less than 1% and the absence of a listing in CISA KEV. However, once the attacker can retrieve the Apple Account after a wipe, they maintain ongoing access to cloud services and personal data. In environments where physical device access is possible, the risk of continued data exposure and credential misuse warrants immediate remediation.
OpenCVE Enrichment