CVE-2025-46279
Permissions Issue in Apple OSes Allows App Installation Disclosure
Publication date: 2025-12-17
Last updated on: 2026-04-02
Assigner: Apple Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apple | ipados | to 18.7.3 (exc) |
| apple | ipados | From 26.0 (inc) to 26.2 (exc) |
| apple | iphone_os | to 18.7.3 (exc) |
| apple | iphone_os | From 26.0 (inc) to 26.2 (exc) |
| apple | macos | to 26.2 (exc) |
| apple | tvos | to 26.2 (exc) |
| apple | visionos | to 26.2 (exc) |
| apple | watchos | to 26.2 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |
Attack-Flow Graph
AI Powered Q&A
How can this vulnerability impact me? :
This vulnerability could impact you by allowing an app to discover which other apps you have installed, potentially exposing your app usage patterns and preferences, which may lead to privacy concerns.
What immediate steps should I take to mitigate this vulnerability?
Update your devices to the fixed versions: watchOS 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, or tvOS 26.2 to address the permissions issue.
Can you explain this vulnerability to me?
This vulnerability is a permissions issue where an app may be able to identify what other apps a user has installed on their device. It was addressed by adding additional restrictions in various Apple operating systems.