Impact
A correctness issue in macOS allows an attacker with physical access to silently re‑store an Apple Account on a device that has been erased, thereby maintaining access to iCloud services, email, and other personal data that would normally require re‑authentication. The weakness involves improper cleanup or deletion logic that controls the storage of Apple Account state and results in the account lingering after a wipe. This persistence can lead to credential compromise and broader exploitation within the Apple ecosystem.
Affected Systems
Apple macOS devices running any version prior to macOS Sonoma 14.8.8 are affected. The issue is fixed in macOS Sonoma 14.8.8 and later; earlier releases of macOS, including older Sonoma versions, remain vulnerable.
Risk and Exploitability
The flaw requires physical possession of the device and the ability to initiate a device erase, which is why the EPSS score is not available and the vulnerability is not listed in CISA KEV. However, the ability to preserve an Apple Account after a wipe elevates the risk of ongoing data exposure and credential misuse, warranting prompt remediation in any environment where physical device access is possible.
OpenCVE Enrichment