Description
The issue was resolved by sanitizing logging. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An app may be able to enumerate a user's installed apps.
Published: 2026-02-11
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure (app enumeration)
Action: Patch
AI Analysis

Impact

The vulnerability allows a malicious app to read system logs that were not properly sanitized. This can be used to enumerate which applications are installed on a device, providing an attacker with target‑specific information. The weakness is an instance of excessive logging (CWE‑532) and can compromise user privacy, though it does not directly lead to code execution or system compromise.

Affected Systems

The affected platforms are Apple iOS and iPadOS. Versions before iOS 18.7.5 (and iOS 26.3) and before iPadOS 18.7.5 (and iPadOS 26.3) are vulnerable. Users of these unpatched OS releases on iPhones and iPads could be exposed to information disclosure.

Risk and Exploitability

The CVSS score of 3.3 indicates low severity, and the EPSS score of less than 1% shows a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog and is likely to be exploited locally by a malicious third‑party app that can read logs, rather than remotely or with elevated privileges. Installing the latest patched OS mitigates the risk entirely.

Generated by OpenCVE AI on April 15, 2026 at 20:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device to iOS 18.7.5 or later (including iOS 26.3) and to iPadOS 18.7.5 or later (including iPadOS 26.3) to apply the logging sanitization fix.
  • If an update is not yet available, remove any third‑party applications that can read system logs to prevent the enumeration of installed apps.
  • Continuously monitor the device for untrusted applications and restrict logging permissions in Settings > Privacy to limit exposure.

Generated by OpenCVE AI on April 15, 2026 at 20:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Apr 2026 21:15:00 +0000

Type Values Removed Values Added
Title Information Disclosure: App Enumeration via Unfiltered Logging

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was resolved by sanitizing logging. This issue is fixed in iOS 26.3 and iPadOS 26.3, iOS 18.7.5 and iPadOS 18.7.5. An app may be able to enumerate a user's installed apps. The issue was resolved by sanitizing logging. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An app may be able to enumerate a user's installed apps.

Thu, 12 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-532
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Feb 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Thu, 12 Feb 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Vendors & Products Apple
Apple ios And Ipados

Wed, 11 Feb 2026 23:15:00 +0000

Type Values Removed Values Added
Description The issue was resolved by sanitizing logging. This issue is fixed in iOS 26.3 and iPadOS 26.3, iOS 18.7.5 and iPadOS 18.7.5. An app may be able to enumerate a user's installed apps.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:18:11.159Z

Reserved: 2025-11-11T14:43:07.865Z

Link: CVE-2026-20663

cve-icon Vulnrichment

Updated: 2026-02-12T21:24:00.640Z

cve-icon NVD

Status : Modified

Published: 2026-02-11T23:16:08.923

Modified: 2026-04-02T19:21:19.590

Link: CVE-2026-20663

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-15T21:00:09Z

Weaknesses