Junglewise Threat Intelligence

CVE-2026-65354: Apple iOS and iPadOS App Store permissions bypass

CVE-2026-65354 · Severity: high · CVSS 8.2 · Published 2026-09-14

Technologies: Apple macOS, Apple Iphone Os, Apple iPadOS. Vendors: Apple.

Executive brief

The App Store framework on iPhones and iPads contains a permissions vulnerability that allows malicious apps to read persistent account identifiers without proper authorization. This could enable attackers to track users across apps or steal account information, compromising user privacy and potentially enabling account takeover attacks.

Technical details

A permissions issue in the App Store framework on iOS 27 and iPadOS 27 allows local apps to read a persistent account identifier (IDFA or similar) without proper sandbox restrictions. The vulnerability is a local privilege escalation requiring the malicious app to be installed on the device. The fix involves additional permission restrictions in iOS 27 and iPadOS 27 released September 14, 2026. This is categorized as CVE-2026-86888 and can be exploited by any app with basic permissions, allowing cross-app tracking or credential harvesting.

Affected products

  • Apple iOS before 27
  • Apple iPadOS before 27

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Fixed in iOS 27 and iPadOS 27

References

Related threats