ZeroHour

CVE-2026-86895

mass

Local App Can Read Persistent Account Identifier in Apple iOS/iPadOS/tvOS/visionOS/watchOS

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

An information disclosure flaw (CWE-200) in Apple's mobile, TV, wearable, and headset operating systems, caused by improper state management, allows a locally installed app to read a persistent account identifier. It is triggered when a malicious or compromised app on the device accesses platform state that exposes the identifier without appropriate isolation. An attacker gains a stable, durable identifier tied to the user's Apple account, which can enable cross-app tracking, profiling, and long-term device-user correlation. All devices running versions of iOS, iPadOS, tvOS, visionOS, or watchOS prior to the 27 releases are affected; note the flaw is rated 7.5 (high) via a CVSS 3.1 vector that lists a network attack vector, though the vendor description indicates local-app exploitation. No public proof-of-concept exists, the issue is not on the CISA KEV list, and no in-the-wild exploitation has been reported.

What to do: Upgrade all Apple devices to iOS 27, iPadOS 27, tvOS 27, visionOS 27, or watchOS 27, and push these updates via MDM in managed fleets. Until patched, restrict app installations to vetted, trusted developers and review enterprise/MDM policies for app allow-lists, since exploitation requires a local app already present on the device. Monitor privacy and analytics settings for untrusted apps collecting unexpected identifiers.

Affected
Apple iOSversions prior to iOS 27
Apple iPadOSversions prior to iPadOS 27
Apple tvOSversions prior to tvOS 27
Apple visionOSversions prior to visionOS 27
Apple watchOSversions prior to watchOS 27
Estimated exposure
mass≈1 billion+ devices (unpatched share of Apple's installed base across iPhone, iPad, Apple TV, Apple Watch, and Vision Pro) — Apple has publicly reported well over 2 billion active devices worldwide, and a large fraction of the iOS/iPadOS/watchOS/tvOS/visionOS installed base will not yet have upgraded to the 27 releases, so the unpatched population plausibly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27, watchOS 27. A local app may be able to read a persistent account identifier.

Vendors
apple
Products
ipados, iphone os, tvos, visionos, watchos
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.