Junglewise Threat Intelligence

CVE-2026-43657: Apple iOS and iPadOS permissions bypass allowing app enumeration

CVE-2026-43657 · Severity: low · CVSS 3.3 · Published 2026-08-25

Technologies: Apple Iphone Os, Apple iPadOS. Vendors: Apple.

Executive brief

A permissions flaw in iOS and iPadOS allows malicious apps to bypass privacy restrictions and enumerate which apps are installed on a device. This could enable attackers to profile user behavior, target other installed applications with tailored attacks, or gather intelligence on device configuration without user awareness or consent.

Technical details

A permissions issue in the Accounts framework allows a malicious app to bypass certain privacy preferences and enumerate installed applications. The vulnerability is local to the device and requires the malicious app to be installed and executed; it does not require network access or elevated privileges. An attacker can gain information about what other apps are present on the device, which is useful for reconnaissance prior to launching targeted attacks. The issue was addressed with additional restrictions in iOS 26.5 and iPadOS 26.5, released on May 11, 2026.

Affected products

  • Apple iOS before 26.5
  • Apple iPadOS before 26.5

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: patched

References

Related threats