Impact
A privacy issue was identified where an application can determine the list of other apps installed on a device. The vulnerability arises from enhanced handling of user preferences that, if not properly shielded, permits leakage of app installation data. This disclosure can reveal user behavior, preferences and potentially sensitive usage patterns, compromising personal privacy.
Affected Systems
The vulnerability affects Apple’s iOS and iPadOS platforms prior to version 27. All releases earlier than iOS 27 and iPadOS 27. An attacker must have an app already installed or be able to install an app on the target device.
Risk and Exploitability
The EPSS score indicates the likelihood of exploitation is less than 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting low or unverified exploitation activity. The attack vector is local, requiring only that a malicious or compromised application be installed on the user’s device. No network or remote exploitation is described. The impact is limited to privacy leakage of installed application information, with no direct capability for further system compromise. The CVSS base score is 7.5 and the EPSS score is less than 1%.
OpenCVE Enrichment