Impact
An information disclosure flaw exists in Apple operating systems where an application can identify other apps installed on the device. The weakness arises from inadequate state management that leaks the presence of additional applications to a malicious app, violating privacy but not providing code execution or denial‑of‑service capabilities. The vulnerability is classified as CWE‑200, representing a failure to restrict access to sensitive information.
Affected Systems
Affected are Apple devices running iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27.
Risk and Exploitability
The CVSS score is 3.3, indicating a low severity impact. The EPSS score is less than 1 %, showing a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker only needs to install a malicious application that can query the system state; no additional vulnerabilities are required, so while the risk to confidentiality is present, the overall likelihood remains low.
OpenCVE Enrichment