Junglewise Threat Intelligence

CVE-2026-82985: Apple Photos smart album configuration disclosure

CVE-2026-82985 · Severity: medium · CVSS 6.5 · Published 2026-09-18

Vendors: Apple.

Executive brief

Apple's Photos app allows users to create "smart albums" that use filters to automatically include photos from specific folders. When a smart album owner shares one of these albums with another user, the recipient's folder configuration is used instead of the owner's intended configuration. This causes unintended files—including their names, IDs, and metadata—from the owner's folders to become visible to the recipient, even though those folders were never meant to be shared.

Technical details

The vulnerability is an information disclosure flaw in how Photos app smart albums handle access control. When a shared smart album applies its filter-based search using the photosSourceFolders configuration, the app uses the viewing user's folder settings rather than the album owner's settings. This allows an attacker with access to a shared smart album to determine file existence and metadata for files in folders outside the owner's intended sharing scope. The attack requires the album owner to explicitly share a filter-based smart album with the attacker; it does not enable access to arbitrary users' albums or files. No patching status is currently documented.

Affected products

  • Apple Photos

Timeline

  • 2026-09-18: disclosed

References