ZeroHour

CVE-2026-64761

mass

Privacy Flaw in Apple iOS/iPadOS Lets Apps Detect Other Installed Apps

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-64761 is an information-exposure flaw (CWE-200) in Apple's iOS and iPadOS that allows an app installed on a device to identify which other apps the user has installed. It is triggered entirely by an app running on the device exploiting improper handling of user preferences, requiring no privileges or user interaction per the CVSS vector. An attacker gains the ability to fingerprint a user's app inventory, enabling invasive profiling, targeted advertising, and inference of sensitive attributes such as health, religion, or financial status from installed apps. All iPhones and iPads running versions prior to iOS 27 and iPadOS 27 are affected, with the issue fixed in those releases. No public proof of concept exists, the flaw is not in CISA's KEV catalog, and no in-the-wild exploitation is known.

What to do: Update iPhones and iPads to iOS 27 or iPadOS 27, which contain the fix. Enterprises should use MDM to enforce the update across fleets and audit third-party apps for excessive data collection. Users should be wary of apps that exhibit aggressive tracking or fingerprinting behavior and remove apps they do not trust.

Affected
Apple iOSversions prior to iOS 27
Apple iPadOSversions prior to iPadOS 27
Estimated exposure
mass≈1 billion+ iPhone and iPad users potentially affected before updating — Apple's global installed base of active iPhones and iPads is widely reported to exceed one billion devices, and any device not yet updated to iOS/iPadOS 27 remains exposed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS 27 and iPadOS 27. An app may be able to identify what other apps a user has installed.

Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.