Executive brief
A privacy vulnerability in iOS and iPadOS allows malicious apps to identify what other apps a user has installed on their device. This information could be used to target users with specific attack vectors, infer sensitive user interests or behaviors, or enable social engineering based on installed software. The issue has been patched in iOS 27 and iPadOS 27.
Technical details
The vulnerability is a privacy issue in the handling of user preferences and app permission mechanisms in iOS/iPadOS. The root cause involves insufficient protection of app preference data, allowing a third-party app to enumerate other installed applications without explicit user consent. The attack requires only that a malicious app be installed and run locally on the device—no network access or special permissions are needed. An attacker can discover the user's installed application landscape to enable targeted social engineering, identify security-sensitive applications, or enable follow-on exploits. The fix improves handling of user preferences in iOS 27 and iPadOS 27.
Affected products
- Apple iOS prior to 27
- Apple iPadOS prior to 27
Timeline
- 2026-09-14: patched: Fixed in iOS 27 and iPadOS 27
- 2026-09-14: disclosed: Published on Apple security releases page