CVE-2026-28836: Security vulnerability
Published Sep 14, 2026
·Updated
A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8.8. An attacker with physical access may be able to silently persist an Apple Account on an erased device.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
macOS Sonomato a version that resolves this vulnerability.Fixed in 14.8.8
Event History
Sep 14, 2026
CVE Published
via MITRE·08:48 PM
Data Sourced
via MITRE·08:48 PM
DescriptionWeakness
Data Sourced
via NVD·09:17 PM
Description
Frequently Asked Questions
1
Who is exposed to this issue?
Devices that have been erased and are accessible to an attacker with physical access may be exposed. The issue could allow the attacker to silently persist an Apple Account on the erased device.
2
What does an attacker need to exploit it?
The attacker needs physical access to the device. No remote attack path is described in the available information.
3
Which update fixes the issue?
Apple states that the issue is fixed in macOS Sonoma 14.8.8.