Junglewise Threat Intelligence

CVE-2026-28833: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS

CVE-2026-28833 · Severity: medium · CVSS 6.2 · Published 2026-03-25

Technologies: Apple macOS, Apple Iphone Os, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A security vulnerability in Apple's iCloud component could allow a malicious application to see a list of all other apps installed on a user's device. While this does not allow the attacker to access data within those apps, it can be used to profile users or identify further targets for attack. This issue affects iPhones, iPads, Macs, and Vision Pro headsets.

Technical details

A permissions vulnerability exists in the iCloud component of multiple Apple operating systems. The flaw stems from insufficient restrictions on app enumeration, allowing a local application to bypass intended privacy boundaries and identify other installed software. This is classified as an improper access control issue (CWE-284). An attacker can exploit this by convincing a user to install a malicious app, which can then gather intelligence about the device's software environment. Apple addressed the issue in version 26.4 of its operating systems by implementing additional permission restrictions.

Affected products

  • Apple iOS Before 26.4
  • Apple iPadOS Before 26.4
  • Apple macOS Tahoe Before 26.4
  • Apple visionOS Before 26.4

Timeline

  • 2026-03-24: patched: Fixed in iOS 26.4, iPadOS 26.4, macOS Tahoe 26.4, and visionOS 26.4
  • 2026-03-25: disclosed

References

Related threats