CVE-2026-64761
Apple · iOS and iPadOS
A privacy vulnerability in Apple iOS and iPadOS allows an installed application to enumerate other applications installed on the user device.
Executive summary
An unauthenticated application on Apple iOS or iPadOS can identify other installed apps, posing a significant privacy risk to users.
Vulnerability
This privacy flaw involves improper handling of user preferences, which allows a malicious or compromised application to bypass sandbox restrictions and query the device for a list of other installed applications. The vulnerability is exploitable by an unauthenticated application without user interaction, as indicated by the CVSS vector.
Business impact
The ability for an application to map the software ecosystem of a device represents a significant privacy violation and potential vector for targeted social engineering or exploit chaining. While the CVSS score of 7.5 reflects a high severity level, the primary impact is the unauthorized disclosure of sensitive user configuration data rather than direct system compromise. Organizations should treat this as a high priority for mobile fleet management due to the potential for sensitive internal app discovery.
Remediation
Immediate Action: Update all Apple devices to iOS 27 or iPadOS 27 or later to implement the vendor provided fix for user preference handling.
Proactive Monitoring: Review mobile device management (MDM) logs for suspicious application behavior or unexpected inter-app communication patterns.
Compensating Controls: Implement mobile application management (MAM) policies to restrict the installation of untrusted or unauthorized applications, thereby reducing the attack surface for potential enumeration.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the broad impact on user privacy and the high CVSS severity rating, administrators must prioritize the deployment of iOS 27 and iPadOS 27 across all corporate-managed devices. Failure to patch may allow malicious applications to gather intelligence on the user environment, which can facilitate further attacks. Immediate application of this update is necessary to ensure the integrity of the mobile device sandbox.
More Apple CVEs all →
History
CVE Brief tracked this CVE 2 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 7.5 (3.1)
- Analyst report written