Description
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A local app may be able to read a persistent account identifier.
Published: 2026-09-14
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

ApermissionsissueinAppleoperatingsystemsallowsalocalapplicationtoreadapersistentaccountidentifier,revealinguserinformationthatshouldbeprotected.Theflawisbasedonsufficientauthorizationchecks,enablingtheapptoaccesedatabeyonditsintendedscope.Thevulnerabilityresultsintheinadvertentdisclosureofsensitivedatawithinthedevicelocalstorage.

Affected Systems

AppleiOS, iPadOS, macOS, tvOS, visionOS, and watchOS versions older than the fixed releases (iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, or watchOS 27) are affected.

Risk and Exploitability

The vulnerability is exploitable locally by installing or running code with application privileges. The CVSS score is 3.3, indicating low severity. The EPSS score is less than 1%, indicating a very low probability of exploitation. The flaw is not listed in the CISA KEV catalog, further suggesting limited public exploitation. Local or in‑device execution is sufficient, but the practical risk remains moderate for users of unpatched systems.

Generated by OpenCVE AI on September 20, 2026 at 22:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the device operating system to the latest available version (iOS 27, iPadOS 27, macOS Golden Gate 27 or later, macOS Tahoe 26.7 or later, tvOS 27, visionOS 27, watchOS 27).
  • Re‑install or obtain applications from trusted sources only, ensuring that they request minimal permissions.
  • Review application permissions in Settings to confirm no unnecessary access is granted to the persistent account identifier.

Generated by OpenCVE AI on September 20, 2026 at 22:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Sun, 20 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title Apple OS Persistent Account Identifier Exposure

Sun, 20 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Title Local App Reads Persistent Account Identifier Due to Permissions Issue
Weaknesses CWE-200

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Tue, 15 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Local App Reads Persistent Account Identifier Due to Permissions Issue
Weaknesses CWE-200

Tue, 15 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A local app may be able to read a persistent account identifier.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-20T00:03:51.055Z

Reserved: 2026-09-08T16:43:41.872Z

Link: CVE-2026-86888

cve-icon Vulnrichment

Updated: 2026-09-17T15:09:31.032Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:39.757

Modified: 2026-09-21T18:02:59.610

Link: CVE-2026-86888

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:15:05Z

Weaknesses
  • CWE-269

    Improper Privilege Management