Junglewise Threat Intelligence

CVE-2026-84603: Apple iOS and iPadOS permissions bypass in App Store

CVE-2026-84603 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple Iphone Os, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A permissions flaw in the App Store component of iOS and iPadOS allows malicious apps to read a persistent account identifier without proper authorization. This identifier could be used to track users across apps or link accounts, potentially exposing user privacy and enabling targeted attacks. The vulnerability affects millions of iPhone and iPad users and has been patched in iOS 27 and iPadOS 27.

Technical details

This is a permissions issue in the App Store framework where additional restrictions were insufficient to prevent unauthorized access to persistent account identifiers. The vulnerability allows a local app to read account identifiers that should require explicit user permission. Attack requires the malicious app to be installed on the device. An attacker can leverage this to correlate user activity across apps or perform account linking without consent. The issue is addressed in iOS 27, iPadOS 27, and watchOS 27 released September 14, 2026.

Affected products

  • Apple iOS before 27
  • Apple iPadOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Fixed in iOS 27, iPadOS 27, and watchOS 27

References

Related threats