CVE-2026-28833 addresses a permissions vulnerability in Apple's iOS, iPadOS, macOS, and visionOS that could allow a malicious application to enumerate a user's installed apps. This issue is resolved in version 26.4 across all affected operating systems. Rated with a CVSS score of 6.2 (Medium), the vulnerability has a local attack vector and low attack complexity, allowing a malicious app to achieve high confidentiality impact by revealing installed software. There is currently no evidence of active exploitation, nor is public exploit code available on platforms like Metasploit or ExploitDB, and it has garnered minimal community or media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 26.4CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 26.4CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
>= 26.0, < 26.4CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
< 26.4CPE matchmatch criteria | cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.