Junglewise Threat Intelligence

CVE-2026-28882: Apple OS installed app enumeration in iCloud and Crash Reporter

CVE-2026-28882 · Severity: medium · CVSS 4 · Published 2026-03-25

Technologies: Apple Tvos, Apple macOS, Apple Iphone Os, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A privacy vulnerability in Apple operating systems could allow a malicious application to see a list of other apps installed on a user's device. While this does not allow access to the data within those apps, it can be used for user profiling or to identify other vulnerable software on the system. This issue affects iPhones, iPads, Macs, Apple TVs, and Apple Watches.

Technical details

A privacy and permissions issue exists in multiple Apple operating systems (iOS, iPadOS, macOS, tvOS, visionOS, and watchOS) within the iCloud and Crash Reporter components. The vulnerability allows a locally installed application to bypass intended privacy restrictions to enumerate the full list of other applications installed on the device. Apple addressed this by improving checks, removing sensitive data from logs, and implementing additional sandbox restrictions. The fix is available in iOS/iPadOS 18.7.9 and 26.4, macOS Tahoe 26.4, and corresponding updates for other Apple platforms.

Affected products

  • Apple iOS Before 18.7.9, before 26.4
  • Apple iPadOS Before 18.7.9, before 26.4
  • Apple macOS Tahoe Before 26.4
  • Apple tvOS Before 26.4
  • Apple visionOS Before 26.4
  • Apple watchOS Before 26.4

Timeline

  • 2026-03-24: patched: Initial release of patches for iOS 26.4 and macOS 26.4
  • 2026-03-25: disclosed
  • 2026-05-11: advisory: Advisory updated to include iOS 18.7.9 and iPadOS 18.7.9 as fixed versions

References

Related threats