Description
An authorization issue was addressed with improved access control. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to read persistent device identifiers.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to persistent device identifiers
Action: Apply Patch
AI Analysis

Impact

Apple identified an improved access control that inadvertently left an authorization gap, allowing applications to read persistent device identifiers that should remain protected. The flaw does not give attackers code execution or other direct system control but exposes a set of uniquely identifying values that could be used for tracking, profiling or other privacy‑compromising purposes. This is effectively a data‑exposure vulnerability, exposing sensitive device information without proper authentication or permission checks.

Affected Systems

The issue affects multiple Apple operating systems, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. Specifically, affected versions are iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27.

Risk and Exploitability

Because the flaw centers on improper access control, the primary exploitation path involves a malicious or compromised application that is granted any user‑level installation. Once installed, the app can request the device’s persistent identifiers and read them without further user consent. The CVSS score of 5.5 indicates moderate severity, the EPSS score is < 1% and the vulnerability is not currently listed in the CISA KEV catalog, indicating a low probability of exploitation, yet the privacy impact remains significant, especially where unverified applications may be installed.

Generated by OpenCVE AI on September 20, 2026 at 22:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest available OS version (iOS 27 or 26.7, iPadOS 27 or 26.7, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27) which contains the access‑control fix
  • For macOS, ensure both Classic and Apple Silicon systems receive the corresponding update, as multiple releases address the issue
  • For tvOS, visionOS, and watchOS users, install the 27 release to close the authorization gap

Generated by OpenCVE AI on September 20, 2026 at 22:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Title Improved Access Control Weakness Exposing Persistent Device Identifiers

Wed, 16 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 16 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Title App Permission Leak of Persistent Device Identifiers via Authorization Issue
Weaknesses CWE-200
CWE-284

Tue, 15 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title App Permission Leak of Persistent Device Identifiers via Authorization Issue
Weaknesses CWE-200
CWE-284

Tue, 15 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An authorization issue was addressed with improved access control. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to read persistent device identifiers.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T12:10:07.160Z

Reserved: 2026-09-01T21:13:23.285Z

Link: CVE-2026-84612

cve-icon Vulnrichment

Updated: 2026-09-16T12:09:27.243Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:36.347

Modified: 2026-09-16T18:25:47.073

Link: CVE-2026-84612

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:30:06Z

Weaknesses