Description
An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27, watchOS 27. A local app may be able to read a persistent account identifier.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

A local application may be able to read a persistent account identifier that is tied to the device. This constitutes a CWE-200 Information Exposure weakness that allows the app to disclose personal information that can be used to track or correlate user activity across services. The vulnerability does not enable code execution, privilege escalation, or denial-of-service, but it does compromise user confidentiality.

Affected Systems

Apple operating systems that run before the 27 releases—namely iOS, iPadOS, tvOS, visionOS, and watchOS—are affected. Each platform’s security state is fixed in the corresponding 27 version, eliminating the vulnerability from those updated releases.

Risk and Exploitability

The CVSS score of 7.5 classifies the issue as high severity. The EPSS score of less than 1% indicates a very low probability that the vulnerability will be actively exploited, and the CVE is not currently listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires the attacker to execute code locally on the target device, typically through a malicious application or compromised app. While public exploitation has not been documented, the confidentiality impact warrants prompt remediation.

Generated by OpenCVE AI on September 20, 2026 at 18:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade all affected devices to the latest release—iOS 27, iPadOS 27, tvOS 27, visionOS 27, or watchOS 27.
  • Update installed applications to the latest versions, ensuring they no longer read the persistent account identifier.
  • Audit app permissions and revoke or limit access for any local application that exposes or uses user identifiers unnecessarily.

Generated by OpenCVE AI on September 20, 2026 at 18:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Title Persistent Account Identifier Disclosure in Apple OS Versions Prior to 27

Wed, 16 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Information Disclosure via Persistent Account Identifier Leak

Wed, 16 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Title Information Disclosure via Persistent Account Identifier Leak
Weaknesses CWE-200

Tue, 15 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27, watchOS 27. A local app may be able to read a persistent account identifier.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Tvos Visionos Watchos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T18:15:36.157Z

Reserved: 2026-09-08T16:43:41.872Z

Link: CVE-2026-86895

cve-icon Vulnrichment

Updated: 2026-09-15T18:15:32.620Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:40.473

Modified: 2026-09-16T01:03:06.730

Link: CVE-2026-86895

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T18:15:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor