Junglewise Threat Intelligence

CVE-2026-84626: Apple iOS and iPadOS information disclosure via app enumeration

CVE-2026-84626 · Severity: low · CVSS 3.3 · Published 2026-09-14

Technologies: Apple Tvos, Apple macOS Golden Gate, Apple watchOS, Apple Visionos, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

iOS and iPadOS contain a privacy vulnerability that allows an installed app to discover which other apps a user has on their device. This information could be used by malicious apps to profile users, enable targeted attacks on other installed apps, or infer sensitive user interests and behaviors. The issue affects multiple Apple operating systems and is fixed in iOS 27, iPadOS 27, and related OS releases.

Technical details

A privacy issue in the Accessibility framework allows a local app to enumerate installed applications on the device by querying what other apps are available. The vulnerability exists in the system's app enumeration logic and was introduced through insufficient state management that did not properly restrict app discovery to authorized contexts. An attacker with an installed app can query the system to identify all other installed apps without requiring explicit user permission or elevated privileges. The fix improves handling of user privacy preferences and state management to prevent unauthorized app enumeration. Patches are available in iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27.

Affected products

  • Apple iOS before 27
  • Apple iPadOS before 27
  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: patched: iOS 27, iPadOS 27, and other OS releases with fixes released
  • 2026-09-14: disclosed

References

Related threats