CVE-2025-43442
7.5Apple · iOS and iPadOS
A permissions vulnerability in Apple iOS and iPadOS allows an application to determine which other applications are installed on the user device.
Executive summary
A high-severity permissions flaw in Apple iOS and iPadOS allows malicious applications to enumerate installed software, potentially leading to unauthorized information disclosure.
Vulnerability
This is a permissions-based flaw where an application with local access can bypass restrictions to identify other applications installed on the system. The vulnerability requires the attacker to have already established a local presence as an application on the device.
Business impact
The ability for an application to map the installed software on a device constitutes a significant privacy risk and potential reconnaissance vector. By identifying specific applications, an attacker can tailor subsequent exploits or social engineering campaigns based on the user's software footprint. With a CVSS score of 7.5, this vulnerability represents a substantial risk to user privacy and device integrity.
Remediation
Immediate Action: Update all affected iOS and iPadOS devices to version 18.7.2 or 26.1 immediately to apply the necessary permission restrictions.
Proactive Monitoring: Review application permissions and audit installed software lists on managed devices for suspicious or unauthorized entries.
Compensating Controls: Implement mobile device management (MDM) policies to restrict the installation of non-approved or untrusted applications, which limits the potential for malicious software to exploit this flaw.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Given the potential for unauthorized data collection regarding a user's digital environment, organizations should prioritize the deployment of the Apple security updates. Ensuring that all fleet devices are running version 18.7.2 or 26.1 is critical to closing this information disclosure path and maintaining the privacy of user device configurations.