Junglewise Threat Intelligence

CVE-2026-65345: Apple iOS permissions issue in App Store

CVE-2026-65345 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple iPadOS, Apple macOS Tahoe, Apple macOS Golden Gate. Vendors: Apple.

Executive brief

Apple iOS and iPadOS contain a permissions vulnerability in the App Store component that allows installed apps to read persistent account identifiers without proper authorization. An attacker with a malicious app could access this sensitive identifier to track or identify users, potentially enabling account takeover or privacy violations across multiple Apple services.

Technical details

A permissions issue in the App Store component fails to properly restrict access to persistent account identifiers. The vulnerability allows a local, already-installed malicious app to read a persistent account identifier without appropriate authorization checks. Attack precondition: the malicious app must be installed on the device. An attacker can exploit this to identify users and potentially link their identity across multiple services. The issue was addressed with additional restrictions in iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.

Affected products

  • Apple iOS before 26.7 and before 27
  • Apple iPadOS before 26.7 and before 27
  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched

References

Related threats