CVE-2026-86895

Apple · iOS and iPadOS

A local application may be able to read a persistent account identifier due to an information disclosure flaw involving improper state management.

Executive summary

Apple has addressed an information disclosure vulnerability in multiple operating systems that could allow a local application to access sensitive persistent account identifiers.

Vulnerability

The vulnerability is an information disclosure flaw caused by improper state management within the operating system. This allows a local, potentially malicious application to bypass privacy boundaries and read persistent account identifiers.

Business impact

The exposure of persistent account identifiers can facilitate unauthorized tracking of users across different applications and services, leading to a loss of user privacy and potential identity correlation. With a CVSS score of 7.5, this high-severity vulnerability poses a significant risk to data confidentiality for enterprise users and mobile device fleets.

Remediation

Immediate Action: Update all affected devices to version 27 or later, as provided in the official Apple security updates.

Proactive Monitoring: Review mobile device management (MDM) logs for unusual application behavior or unexpected requests for account-related information.

Compensating Controls: Implement strict application vetting processes and utilize mobile security solutions that restrict the ability of untrusted third party applications to access system level identifiers.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Given the high severity of this information disclosure vulnerability, administrators should prioritize the deployment of the version 27 updates across all managed Apple devices. Ensuring that devices are running the latest software is the most effective method to prevent local applications from accessing sensitive account identifiers and maintaining system integrity.

More Apple CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 7.5 (3.1)
  4. Analyst report written

Sources