CVE-2026-28836

A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8.8. An attacker with physical access may be able to silently persist an Apple Account on an erased device.
References
Configurations

No configuration.

History

17 Sep 2026, 16:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CWE CWE-359

Information

Published : 2026-09-14 21:17

Updated : 2026-09-17 16:17


NVD link : CVE-2026-28836

Mitre link : CVE-2026-28836

CVE.ORG link : CVE-2026-28836


JSON object : View

Products Affected

No product.

CWE
CWE-359

Exposure of Private Personal Information to an Unauthorized Actor