Junglewise Threat Intelligence

CVE-2026-86884: Apple iOS and iPadOS App Store permissions issue

CVE-2026-86884 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple Tvos, Apple macOS, Apple Iphone Os, Apple watchOS, Apple iPadOS. Vendors: Apple.

Executive brief

Apple's App Store framework on iOS and iPadOS contains a permissions vulnerability that allows installed applications to read persistent account identifiers without proper authorization. This could enable malicious apps to track users across services or link user identity to unauthorized activities, affecting millions of iPhone and iPad users.

Technical details

A permissions issue in the App Store component was addressed with additional restrictions in iOS 27, iPadOS 27, and macOS Golden Gate 27. The vulnerability allows a local app to read a persistent account identifier that should have been protected. The attack requires an installed malicious application; no network access or special user interaction is needed beyond installing and running the app. An attacker can exfiltrate user identifiers for tracking or account linking purposes. The issue is fixed in iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, and watchOS 27, released September 14, 2026.

Affected products

  • Apple iOS before 27
  • Apple iPadOS before 27
  • Apple macOS before Golden Gate 27
  • Apple tvOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched

References

Related threats