Impact
The vulnerability is a permissions issue that allows a malicious application to list all applications installed on an iOS or iPadOS device. The primary impact is the disclosure of installed app names and potentially package identifiers, which can be used to infer user activity, identify potential target apps for further attacks, or gather intelligence on the device environment. This is a direct information‑exposure flaw that could undermine user privacy, and it does not lead to code execution or privilege escalation by itself.
Affected Systems
Apple iOS and iPadOS devices running versions earlier than 26.5 are affected. The issue is fixed in iOS 26.5 and iPadOS 26.5, so any device with an older operating system is vulnerable.
Risk and Exploitability
The CVSS score of 3.3 indicates low severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting current exploitation activity is unknown. The attack vector appears to be local; a malicious application that a user installs from the App Store or a side‑loaded package can trigger the enumeration API. Because the flaw permits only disclosure of registry information, the likelihood of catastrophic damage is limited, but the violation of privacy and potential for targeted follow‑up attacks still warrants prompt mitigation.
OpenCVE Enrichment