Junglewise Threat Intelligence

CVE-2026-86888: Apple App Store permissions issue allowing persistent account identifier exposure

CVE-2026-86888 · Severity: low · CVSS 3.3 · Published 2026-09-14

Technologies: Apple Tvos, Apple macOS, Apple Iphone Os, Apple watchOS, Apple Visionos, Apple iPadOS, Apple macOS Golden Gate. Vendors: Apple.

Executive brief

A local app on Apple devices can read a persistent account identifier through an App Store permissions flaw. This allows malicious apps installed on a user's device to access identifying information that could be used for tracking or account linking without proper authorization.

Technical details

A permissions issue in the App Store framework allowed local applications to read a persistent account identifier without proper authorization checks. The vulnerability is local in nature, requiring the attacker to run code on the target device as a local app. The root cause was insufficient access control restrictions on account identifier data. An attacker with a malicious app installed on a user's device could exploit this to read the persistent account identifier. The issue was fixed by adding additional permission restrictions in iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27.

Affected products

  • Apple iOS before 27
  • Apple iPadOS before 27
  • Apple macOS Golden Gate before 27
  • Apple macOS Tahoe before 26.7
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched

References

Related threats