---
id: CVE-2026-28836
title: A correctness issue was addressed with improved checks
summary: >-
  A correctness issue was addressed with improved checks. This issue is fixed in
  macOS Sonoma 14.8.8. An attacker with physical access may be able to silently
  persist an Apple Account on an erased device.
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-359
vendor: apple
product: macos
affected:
  - macos < 14.8.8
patched:
  - macos 14.8.8
published: '2026-09-14'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T14:38:19.130'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-28836'
references:
  - url: 'https://support.apple.com/en-us/128072'
    label: product-security@apple.com
tags:
  - nvd
  - cve.org
epss: 0.00185
epssPercentile: 0.08298
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-17T15:13:42.858491Z'
ingestedAt: '2026-09-14T21:15:17.526Z'
---

## Overview

A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8.8. An attacker with physical access may be able to silently persist an Apple Account on an erased device.

## Affected

- `macos < 14.8.8`

## Remediation

Upgrade past the affected range:

- `macos 14.8.8`
