VYPR
Low severity3.3NVD Advisory· Published Dec 17, 2025· Updated Apr 2, 2026

CVE-2025-46279

CVE-2025-46279

Description

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. An app may be able to identify what other apps a user has installed.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A permissions issue in Apple operating systems allows an app to identify other installed apps, addressed with additional restrictions.

Vulnerability

Overview CVE-2025-46279 is a permissions issue in Apple operating systems that allows an app to identify what other apps a user has installed. The root cause is insufficient restrictions on app queries, enabling unauthorized enumeration of installed applications [1][2][4].

Exploitation

An attacker would need to have an app installed on the target device. No additional privileges are required beyond normal app sandbox permissions. The app can then probe the system to detect the presence of other apps, potentially without user awareness.

Impact

This information disclosure can be used for device fingerprinting, targeted advertising, or to infer user interests. While the CVSS score is low (3.3), the privacy implications are significant as it leaks the user's app inventory.

Mitigation

Apple addressed the issue with additional restrictions in iOS 18.7.3, iPadOS 18.7.3, iOS 26.2, iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, and watchOS 26.2 [1][2][4]. Users should update to the latest available versions.

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

9

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.