Impact
A permissions flaw lets an installed application discover which other applications are present on the device, exposing a list of user‑installed software. This disclosure can reveal user habits or installed services but does not compromise integrity or availability of the operating system.
Affected Systems
Apple’s iOS, iPadOS, macOS, and visionOS are affected. The flaw is resolved in iOS 18.7.7 and iOS 26.4, iPadOS 18.7.7 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, and visionOS 26.4. Versions older than these remain vulnerable unless updated.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate severity, and an EPSS score below 1 % suggests exploitation is unlikely under current conditions. The vulnerability isn’t listed in CISA’s KEV catalog. It can only be exploited by an application that has been installed on the device—so the attack vector is local, depending on user‑initiated installation of malicious software. No remote or privilege escalation mechanisms are described in the available data.
OpenCVE Enrichment