Junglewise Threat Intelligence

CVE-2026-86895: Apple CloudKit information disclosure in persistent account identifiers

CVE-2026-86895 · Severity: high · CVSS 7.5 · Published 2026-09-14

Technologies: Apple Tvos, Apple Iphone Os, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

CloudKit is Apple's cloud database and synchronization service used by many iOS and tvOS apps to store and sync user data. A flaw in CloudKit's state management allows a local app to read persistent account identifiers without proper authorization, potentially exposing sensitive user identity information. This could enable app developers or malicious apps to track users across services or link their identities in unexpected ways.

Technical details

CVE-2026-86895 is an information disclosure vulnerability in Apple CloudKit caused by improper state management of persistent account identifiers. The vulnerability allows a local application (with network/local attack surface) to read account identifiers that should be restricted. The fix involves improved state management to enforce proper authorization checks. No preconditions such as user interaction or elevated privileges are required beyond the ability to run a local app. An attacker can achieve unauthorized disclosure of user account identifiers. The vulnerability is patched in iOS 27, iPadOS 27, tvOS 27, visionOS 27, and watchOS 27, released September 14, 2026.

Affected products

  • Apple iOS before 27
  • Apple iPadOS before 27
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: patched: Fixed in iOS 27, iPadOS 27, tvOS 27, visionOS 27, and watchOS 27
  • 2026-09-14: disclosed: Published in Apple security bulletins

References

Related threats