Description
A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to enumerate a user's installed apps.
Published: 2026-03-25
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Exposure
Action: Immediate Update
AI Analysis

Impact

A privacy vulnerability permits an application to enumerate the list of apps installed on an Apple device, revealing user behavior and installed software. The flaw is classified as an information disclosure weakness and could lead to sensitive data exposure without user consent.

Affected Systems

It affects all Apple operating systems including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. Fixed versions are iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sonoma 14.8.5 and macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, and watchOS 26.4. Devices running earlier releases remain vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate risk for privacy compromise. EPSS is below 1 %, and the vulnerability is not listed in the CISA KEV catalog, suggesting a low likelihood of malicious exploitation in the wild. Based on the description, it is inferred that the attack vector is local, requiring a malicious or compromised application with sufficient privileges on the device. The impact is limited to privacy violations rather than full system compromise.

Generated by OpenCVE AI on March 25, 2026 at 22:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest iOS, iPadOS, macOS, tvOS, visionOS, and watchOS releases that contain the fix.
  • Verify that the device is running at least iOS 18.7.7 or iOS 26.4, iPadOS 18.7.7 or iPadOS 26.4, macOS 14.8.5 or macOS 26.4, tvOS 26.4, visionOS 26.4, or watchOS 26.4.
  • If an immediate update is not possible, restrict permissions for installed apps or remove any untrusted applications to reduce potential exposure.
  • Enable automatic updates to receive future fixes automatically.
  • Keep an eye on Apple security advisories for additional guidance.

Generated by OpenCVE AI on March 25, 2026 at 22:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 26 Mar 2026 12:30:00 +0000

Type Values Removed Values Added
Title Installed App Enumeration Privacy Leak Privacy Disclosure via Installed Apps Enumeration on Apple Platforms

Wed, 25 Mar 2026 22:00:00 +0000

Type Values Removed Values Added
Title Installed App Enumeration Privacy Leak

Wed, 25 Mar 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 25 Mar 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 25 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Wed, 25 Mar 2026 01:00:00 +0000

Type Values Removed Values Added
Description A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to enumerate a user's installed apps.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:21:56.695Z

Reserved: 2026-03-03T16:36:03.974Z

Link: CVE-2026-28878

cve-icon Vulnrichment

Updated: 2026-03-25T19:54:31.503Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-25T01:17:11.620

Modified: 2026-03-25T21:29:58.040

Link: CVE-2026-28878

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-26T12:17:52Z

Weaknesses