Impact
An application running with local installation privileges can read a persistent account identifier that was not normally exposed. This permission misconfiguration allows the disclosure of a unique identifier tied to the device, which could be used to track user activity or associate data with the user. The vulnerability is a classic information exposure due to insufficient access controls on the account identifier storage. The impact is limited to confidentiality of the identifier, and does not affect system integrity or availability.
Affected Systems
Apple iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27 are all affected.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while the EPSS score of less than 1% suggests that exploitation is unlikely at present. The vulnerability is not listed in CISA KEV, indicating no known widespread exploitation yet. Based on the description, the likely attack vector is local execution of an application that has already been installed on the device.
OpenCVE Enrichment