Description
A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8.8. An attacker with physical access may be able to silently persist an Apple Account on an erased device.
Published: 2026-09-14
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Apple Account persistence on erased macOS devices
Action: Patch
AI Analysis

Impact

A correctness issue in macOS allows an attacker with physical access to silently recover an Apple Account after a device has been erased. The vulnerability stems from inadequate cleanup of account state during a wipe, enabling the account to remain cached and automatically restored. This allows the attacker to access iCloud services, email, and other personal data that would normally require re‑authentication, potentially exposing credentials and sensitive information.

Affected Systems

Apple macOS devices running any version prior to macOS Sonoma 14.8.8 are affected. The issue is addressed in macOS Sonoma 14.8.8; earlier releases, including older versions of Sonoma, remain vulnerable.

Risk and Exploitability

The flaw requires physical possession of the device and the ability to initiate a device erase, which explains the EPSS score of less than 1% and the absence of a listing in CISA KEV. However, once the attacker can retrieve the Apple Account after a wipe, they maintain ongoing access to cloud services and personal data. In environments where physical device access is possible, the risk of continued data exposure and credential misuse warrants immediate remediation.

Generated by OpenCVE AI on September 20, 2026 at 20:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade all affected macOS devices to macOS Sonoma 14.8.8, which includes the fix for the persistence issue.
  • Enable device encryption such as FileVault to ensure data remains protected even if a device is physically accessed.
  • Deploy or enforce remote wipe command through Mobile Device Management (MDM) to perform a full wipe, guaranteeing removal of all Apple account data.

Generated by OpenCVE AI on September 20, 2026 at 20:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sun, 20 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Apple Account Persistence on Erased macOS Devices

Fri, 18 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-359
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Physical Access Enables Silent Apple Account Persistence on Erased macOS Devices
Weaknesses CWE-284

Tue, 15 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Title Physical Access Enables Silent Apple Account Persistence on Erased macOS Devices
Weaknesses CWE-284

Mon, 14 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8.8. An attacker with physical access may be able to silently persist an Apple Account on an erased device.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T15:14:00.363Z

Reserved: 2026-03-03T16:36:03.969Z

Link: CVE-2026-28836

cve-icon Vulnrichment

Updated: 2026-09-17T15:13:09.955Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:05.047

Modified: 2026-09-18T14:38:19.130

Link: CVE-2026-28836

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:45:03Z

Weaknesses
  • CWE-359

    Exposure of Private Personal Information to an Unauthorized Actor