CVE-2026-28836: Apple macOS

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8.8. An attacker with physical access may be able to silently persist an Apple Account on an erased device.

Affected products

  • Apple macOS: before 14.8.8 (fixed in 14.8.8)

Published 2026-09-14. Last modified 2026-09-18.