CVE-2026-86895
massLocal App Can Read Persistent Account Identifier in Apple iOS/iPadOS/tvOS/visionOS/watchOS
An information disclosure flaw (CWE-200) in Apple's mobile, TV, wearable, and headset operating systems, caused by improper state management, allows a locally installed app to read a persistent account identifier. It is triggered when a malicious or compromised app on the device accesses platform state that exposes the identifier without appropriate isolation. An attacker gains a stable, durable identifier tied to the user's Apple account, which can enable cross-app tracking, profiling, and long-term device-user correlation. All devices running versions of iOS, iPadOS, tvOS, visionOS, or watchOS prior to the 27 releases are affected; note the flaw is rated 7.5 (high) via a CVSS 3.1 vector that lists a network attack vector, though the vendor description indicates local-app exploitation. No public proof-of-concept exists, the issue is not on the CISA KEV list, and no in-the-wild exploitation has been reported.
What to do: Upgrade all Apple devices to iOS 27, iPadOS 27, tvOS 27, visionOS 27, or watchOS 27, and push these updates via MDM in managed fleets. Until patched, restrict app installations to vetted, trusted developers and review enterprise/MDM policies for app allow-lists, since exploitation requires a local app already present on the device. Monitor privacy and analytics settings for untrusted apps collecting unexpected identifiers.
| Apple iOS | versions prior to iOS 27 |
| Apple iPadOS | versions prior to iPadOS 27 |
| Apple tvOS | versions prior to tvOS 27 |
| Apple visionOS | versions prior to visionOS 27 |
| Apple watchOS | versions prior to watchOS 27 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27, watchOS 27. A local app may be able to read a persistent account identifier.
- Vendors
- apple
- Products
- ipados, iphone os, tvos, visionos, watchos
- Weakness
- CWE-200
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.