SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-28836

UNKNOWN · CVSS N/A EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A correctness issue in macOS allows an attacker with physical access to potentially maintain an Apple Account on a device that has been erased, posing a risk of unauthorized access to user data. This vulnerability has been addressed in macOS Sonoma 14.8.8, and organizations using affected versions should prioritize updating to mitigate the risk of account persistence and data exposure. Users with devices that could be physically accessed by unauthorized individuals should also consider upgrading to the latest version to enhance their security posture.

CVE
CVE-2026-28836
Severity
UNKNOWN
CVSS
N/A
EPSS
0.17%

Original NVD Description

A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8.8. An attacker with physical access may be able to silently persist an Apple Account on an erased device.