Description
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A local app may be able to read a persistent account identifier.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

An application running with local installation privileges can read a persistent account identifier that was not normally exposed. This permission misconfiguration allows the disclosure of a unique identifier tied to the device, which could be used to track user activity or associate data with the user. The vulnerability is a classic information exposure due to insufficient access controls on the account identifier storage. The impact is limited to confidentiality of the identifier, and does not affect system integrity or availability.

Affected Systems

Apple iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27 are all affected.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity, while the EPSS score of less than 1% suggests that exploitation is unlikely at present. The vulnerability is not listed in CISA KEV, indicating no known widespread exploitation yet. Based on the description, the likely attack vector is local execution of an application that has already been installed on the device.

Generated by OpenCVE AI on September 20, 2026 at 23:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest releases that include the fix, such as iOS 26.7 or later and iPadOS 26.7 or later.
  • Upgrade macOS devices to macOS Golden Gate 27, Sequoia 15.8, or Tahoe 26.7, as well as upgrading tvOS, visionOS, and watchOS to version 27 or later.
  • If an upgrade is not immediately feasible, restrict installation of local apps and monitor for suspicious activity, until the patch can be applied.

Generated by OpenCVE AI on September 20, 2026 at 23:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Title Persistent Account Identifier Disclosure in Apple Operating Systems

Sun, 20 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 16 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 16 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Title Local App May Read Persistent Account Identifier

Wed, 16 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title Local App May Read Persistent Account Identifier
Weaknesses CWE-200
CWE-284

Tue, 15 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A local app may be able to read a persistent account identifier.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T12:16:29.486Z

Reserved: 2026-09-01T21:13:17.757Z

Link: CVE-2026-84583

cve-icon Vulnrichment

Updated: 2026-09-16T12:15:51.775Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:34.377

Modified: 2026-09-16T18:24:53.890

Link: CVE-2026-84583

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:45:06Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor