ZeroHour

CVE-2026-20683

mass

Sign In With Apple Auth Flaw Exposes Apple Accounts on iOS, macOS, visionOS

CVSS
EPSS
Published
()
Modified
AI analysis

CVE-2026-20683 is an authentication weakness in Apple's Sign In With Apple flow caused by improper state management, allowing an app on the device to abuse the authentication flow and gain access to the user's Apple Account. Exploitation requires a malicious or vulnerable app already present on an affected iPhone, iPad, Mac, or Vision Pro; no separate network exposure is needed. A successful attacker could potentially access the victim's Apple Account, which typically gates iCloud data, purchases, and linked services. The flaw affects devices running iOS/iPadOS versions prior to 27, macOS prior to Sequoia 15.8 / Tahoe 26.7 / Golden Gate 27, and visionOS prior to 27, all fixed in Apple's September 2025 release wave. No public proof-of-concept or in-the-wild exploitation has been reported, and the issue is not on the CISA KEV list.

What to do: Update all Apple devices immediately to iOS 27 / iPadOS 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, or visionOS 27, and use MDM or Apple's rapid security response tooling to force fleet-wide patching. Review the list of apps authorized to use Sign In With Apple (Settings > Apple Account > Sign-In and Security) and revoke access for any untrusted or unknown third-party apps. Audit enterprise app inventories for apps that initiate Sign In With Apple flows, since a malicious app on the device is the delivery vector.

Affected
Apple iOSversions prior to iOS 27
Apple iPadOSversions prior to iPadOS 27
Apple macOS Golden Gateversions prior to macOS Golden Gate 27
Apple macOS Sequoiaversions prior to macOS Sequoia 15.8
Apple macOS Tahoeversions prior to macOS Tahoe 26.7
Apple visionOSversions prior to visionOS 27
Estimated exposure
mass≈1-2 billion Apple devices potentially exposed until patched (Apple's active install base exceeds 2 billion devices) — Apple has publicly stated more than 2 billion active devices in use, and any unpatched iPhone, iPad, Mac, or Vision Pro is potentially affected until updated to the fixed releases.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An authentication issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27. An app may be able to use the Sign In With Apple authentication flow to access the user's Apple Account.

In the news

Apple Updates Everything, (Mon, Sep 14th)

Apple patched a record 261 vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS 27, and other platforms, with none flagged as exploited.

Apple's annual OS update shipped iOS/iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27, and visionOS 27 plus bug-fix releases for the 26 and 15 branches, fixing a record 261 vulnerabilities. Notable issues include multiple kernel flaws allowing root privilege escalation (CVE-2026-43689, CVE-2026-43691, CVE-2026-43698, CVE-2026-43786), remote code execution in CUPS (CVE-2026-43692), kernel memory corruption via malicious NFS servers (CVE-2026-43686, CVE-2026-43687), and WebKit memory corruption from crafted web content (CVE-2026-43715). No vulnerabilities are labeled as actively exploited, and Apple does not assign per-CVE severities. Users report iOS 26.7 being downloaded when iOS 27 is intended, and tools like Little Snitch and BlockBlock need updates before upgrading to macOS 27.