Junglewise Threat Intelligence

CVE-2026-84583: Apple iOS and iPadOS permissions issue in App Store

CVE-2026-84583 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple Tvos, Apple macOS Golden Gate, Apple watchOS, Apple Visionos, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

A permissions flaw in the App Store component allows a locally installed app to read a persistent account identifier without proper authorization. An attacker with a malicious app installed on a user's device could use this identifier to track the user across services or link accounts, compromising privacy and potentially enabling account-based attacks.

Technical details

This vulnerability is a permissions issue in the App Store framework that allows a local app to read a persistent account identifier that should be restricted. The root cause is insufficient access controls on sensitive account identifiers stored by the App Store. An attacker must have a malicious app installed on the target device; no network access or user interaction is required beyond the initial app installation. Exploitation enables reading a stable identifier that could be used for cross-app tracking or account linkage. The issue was fixed in iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27 by adding additional permission restrictions.

Affected products

  • Apple iOS before 27
  • Apple iPadOS before 27
  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched

References

Related threats