Description
An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to identify what other apps a user has installed.
Published: 2026-09-14
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

An information disclosure flaw exists in Apple operating systems where an application can identify other apps installed on the device. The weakness arises from inadequate state management that leaks the presence of additional applications to a malicious app, violating privacy but not providing code execution or denial‑of‑service capabilities. The vulnerability is classified as CWE‑200, representing a failure to restrict access to sensitive information.

Affected Systems

Affected are Apple devices running iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27.

Risk and Exploitability

The CVSS score is 3.3, indicating a low severity impact. The EPSS score is less than 1 %, showing a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker only needs to install a malicious application that can query the system state; no additional vulnerabilities are required, so while the risk to confidentiality is present, the overall likelihood remains low.

Generated by OpenCVE AI on September 20, 2026 at 19:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest OS update that includes the fix for iOS 26.7/27, iPadOS 26.7/27, macOS Golden Gate 27, Sequoia 15.8, Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27.
  • Limit the permissions given to applications that request access to the installed‑app list, and remove or block any software that can query this information until a patch is applied.
  • Monitor the Apple Support portal and other vendor channels for any future updates or additional mitigations related to app‑enumeration disclosure.

Generated by OpenCVE AI on September 20, 2026 at 19:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Title Information Disclosure Allowing App Enumeration on Apple Operating Systems

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Thu, 17 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title Information Disclosure Allowing App Enumeration on Apple Operating Systems

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Information Disclosure via Improper State Management Allowing App Enumeration
Weaknesses CWE-200

Tue, 15 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Information Disclosure via Improper State Management Allowing App Enumeration
Weaknesses CWE-200

Tue, 15 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to identify what other apps a user has installed.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T16:51:27.790Z

Reserved: 2026-09-01T21:13:23.287Z

Link: CVE-2026-84626

cve-icon Vulnrichment

Updated: 2026-09-17T16:51:19.988Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:37.630

Modified: 2026-09-18T19:35:56.493

Link: CVE-2026-84626

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T19:15:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor