Executive brief
A privacy vulnerability in Apple operating systems could allow a malicious application to see a list of all other apps installed on a user's device. While this does not grant access to the data inside those apps, it allows developers to track user behavior and profile interests without permission. This issue affects iPhones, iPads, Macs, and Apple Watches, and has been resolved in the latest software updates.
Technical details
A privacy vulnerability (CWE-200) exists in the Crash Reporter component of multiple Apple operating systems. The root cause was the inclusion of sensitive metadata that allowed a local application to enumerate the full list of other installed applications on the device without appropriate permissions. An attacker could exploit this by distributing a malicious app that gathers intelligence on the user's software environment. Apple addressed the issue by removing the sensitive data from the affected component. Patches are available in iOS 18.7.7/26.4, macOS 15.7.7/14.8.5/26.4, and corresponding versions for tvOS, visionOS, and watchOS.
Affected products
- Apple iOS before 18.7.7, 26.0 to 26.4
- Apple iPadOS before 18.7.7, 26.0 to 26.4
- Apple macOS Sequoia before 15.7.7
- Apple macOS Sonoma before 14.8.5
- Apple macOS Tahoe before 26.4
- Apple tvOS before 26.4
- Apple visionOS before 26.4
- Apple watchOS before 26.4
Timeline
- 2026-03-24: patched: Initial release of fixes for iOS 26.4 and others.
- 2026-03-25: disclosed: NVD publication date.
- 2026-05-11: advisory: Last modified by Apple to include macOS Sequoia 15.7.7.