CVE-2026-64761
massPrivacy Flaw in Apple iOS/iPadOS Lets Apps Detect Other Installed Apps
CVE-2026-64761 is an information-exposure flaw (CWE-200) in Apple's iOS and iPadOS that allows an app installed on a device to identify which other apps the user has installed. It is triggered entirely by an app running on the device exploiting improper handling of user preferences, requiring no privileges or user interaction per the CVSS vector. An attacker gains the ability to fingerprint a user's app inventory, enabling invasive profiling, targeted advertising, and inference of sensitive attributes such as health, religion, or financial status from installed apps. All iPhones and iPads running versions prior to iOS 27 and iPadOS 27 are affected, with the issue fixed in those releases. No public proof of concept exists, the flaw is not in CISA's KEV catalog, and no in-the-wild exploitation is known.
What to do: Update iPhones and iPads to iOS 27 or iPadOS 27, which contain the fix. Enterprises should use MDM to enforce the update across fleets and audit third-party apps for excessive data collection. Users should be wary of apps that exhibit aggressive tracking or fingerprinting behavior and remove apps they do not trust.
| Apple iOS | versions prior to iOS 27 |
| Apple iPadOS | versions prior to iPadOS 27 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS 27 and iPadOS 27. An app may be able to identify what other apps a user has installed.
- Weakness
- CWE-200
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.