Impact
A privacy vulnerability permits an application to enumerate the list of apps installed on an Apple device, revealing user behavior and installed software. The flaw is classified as an information disclosure weakness and could lead to sensitive data exposure without user consent.
Affected Systems
It affects all Apple operating systems including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. Fixed versions are iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sonoma 14.8.5 and macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, and watchOS 26.4. Devices running earlier releases remain vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk for privacy compromise. EPSS is below 1 %, and the vulnerability is not listed in the CISA KEV catalog, suggesting a low likelihood of malicious exploitation in the wild. Based on the description, it is inferred that the attack vector is local, requiring a malicious or compromised application with sufficient privileges on the device. The impact is limited to privacy violations rather than full system compromise.
OpenCVE Enrichment