Executive brief
A privacy vulnerability in Apple operating systems could allow a malicious application to see a list of other apps installed on a user's device. While this does not allow access to the data within those apps, it can be used for user profiling or to identify other vulnerable software on the system. This issue affects iPhones, iPads, Macs, Apple TVs, and Apple Watches.
Technical details
A privacy and permissions issue exists in multiple Apple operating systems (iOS, iPadOS, macOS, tvOS, visionOS, and watchOS) within the iCloud and Crash Reporter components. The vulnerability allows a locally installed application to bypass intended privacy restrictions to enumerate the full list of other applications installed on the device. Apple addressed this by improving checks, removing sensitive data from logs, and implementing additional sandbox restrictions. The fix is available in iOS/iPadOS 18.7.9 and 26.4, macOS Tahoe 26.4, and corresponding updates for other Apple platforms.
Affected products
- Apple iOS Before 18.7.9, before 26.4
- Apple iPadOS Before 18.7.9, before 26.4
- Apple macOS Tahoe Before 26.4
- Apple tvOS Before 26.4
- Apple visionOS Before 26.4
- Apple watchOS Before 26.4
Timeline
- 2026-03-24: patched: Initial release of patches for iOS 26.4 and macOS 26.4
- 2026-03-25: disclosed
- 2026-05-11: advisory: Advisory updated to include iOS 18.7.9 and iPadOS 18.7.9 as fixed versions