Junglewise Threat Intelligence

CVE-2026-84628: Apple iOS Keychain access bypass in Accounts

CVE-2026-84628 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple Tvos, Apple macOS, Apple Iphone Os, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A flaw in Apple's account management system allows sandboxed apps to improperly access the System Keychain, which stores sensitive credentials and authentication tokens. An attacker could exploit this to steal user passwords, authentication tokens, and other sensitive data stored in the Keychain without proper authorization, potentially leading to account takeover and unauthorized access to user services.

Technical details

An authorization issue in the Accounts framework was caused by improper state management, allowing a sandboxed app to bypass authorization checks and access System Keychain contents. The vulnerability affects iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. An attacker needs local code execution (sandboxed app installation) to trigger the flaw. The vulnerability was patched in iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27 released September 14, 2026.

Affected products

  • Apple iOS prior to 27
  • Apple iPadOS prior to 27
  • Apple macOS prior to Golden Gate 27
  • Apple tvOS prior to 27
  • Apple visionOS prior to 27
  • Apple watchOS prior to 27

Timeline

  • 2026-09-14: disclosed: CVE-2026-84628 disclosed as part of iOS 27 and other OS release advisories
  • 2026-09-14: patched: Fixed in iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27

References

Related threats