Executive brief
A permissions flaw in the App Store component of iOS and iPadOS allows malicious apps to read a persistent account identifier without proper authorization. This identifier could be used to track users across apps or link accounts, potentially exposing user privacy and enabling targeted attacks. The vulnerability affects millions of iPhone and iPad users and has been patched in iOS 27 and iPadOS 27.
Technical details
This is a permissions issue in the App Store framework where additional restrictions were insufficient to prevent unauthorized access to persistent account identifiers. The vulnerability allows a local app to read account identifiers that should require explicit user permission. Attack requires the malicious app to be installed on the device. An attacker can leverage this to correlate user activity across apps or perform account linking without consent. The issue is addressed in iOS 27, iPadOS 27, and watchOS 27 released September 14, 2026.
Affected products
- Apple iOS before 27
- Apple iPadOS before 27
- Apple watchOS before 27
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched: Fixed in iOS 27, iPadOS 27, and watchOS 27