Junglewise Threat Intelligence

CVE-2026-86893: Apple iOS/iPadOS/tvOS/visionOS/watchOS permissions issue in CloudKit

CVE-2026-86893 · Severity: low · CVSS 3.3 · Published 2026-09-14

Technologies: Apple Tvos, Apple Iphone Os, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

Apple's CloudKit service, used for cloud-based app data synchronization and storage, contains a permissions flaw that allows third-party applications to read device names without proper authorization. This permissions bypass could expose identifying information about the device, potentially enabling device fingerprinting or targeted attacks. The issue affects iPhone, iPad, Apple TV, Apple Vision Pro, and Apple Watch devices running vulnerable OS versions.

Technical details

CVE-2026-86893 is a permissions issue in Apple's CloudKit framework where an app may read device name information despite insufficient authorization controls. The vulnerability stems from inadequate state management in the permissions mechanism protecting CloudKit's device name metadata. No authentication bypass is required—any app can trigger this disclosure through normal CloudKit API calls. The attack is local and does not require user interaction beyond installing the app. Apple addressed this issue by implementing additional access restrictions to the CloudKit permissions model, preventing unauthorized device name disclosure.

Affected products

  • Apple iOS before 27
  • Apple iPadOS before 27
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Fixed in iOS 27, iPadOS 27, tvOS 27, visionOS 27, and watchOS 27

References

Related threats