Junglewise Threat Intelligence

CVE-2026-28836: Apple macOS Sonoma authentication bypass in Account handling

CVE-2026-28836 · Severity: medium · CVSS 6.1 · Published 2026-09-14

Technologies: Apple macOS. Vendors: Apple.

Executive brief

macOS Sonoma's Account management system contains a logic flaw that allows an attacker with physical access to a device to silently restore and persist an Apple Account even after the device has been erased. An attacker could exploit this to regain access to a wiped device and restore their account credentials without user interaction, compromising the device's security and user privacy.

Technical details

This vulnerability is a correctness issue in the Account subsystem of macOS Sonoma involving improper state management during device erasure and account recovery. An attacker with physical access can exploit this flaw to persist an Apple Account on an erased device, silently restoring account credentials and bypassing normal device reset security measures. The issue was addressed through improved validation checks. While a detailed root cause is not disclosed, the attack requires physical device access and succeeds even when intentional erasure has occurred. The fix is available in macOS Sonoma 14.8.8.

Affected products

  • Apple macOS Sonoma before 14.8.8

Timeline

  • 2026-07-27: patched: Fixed in macOS Sonoma 14.8.8
  • 2026-09-14: disclosed

References

Related threats