Apple iOS and iPadOS Keystroke Monitoring Vulnerability

Vulnerability

A vulnerability exists in the LaunchServices component of iOS and iPadOS, allowing apps to monitor keystrokes without user permission. This issue affects iOS 18.7, iPadOS 18.7, iOS 26, and iPadOS 26. The vulnerability arises from insufficient checks, which could enable unauthorized keystroke tracking.

Impact

Exploitation of this vulnerability could lead to unauthorized monitoring of user keystrokes, potentially allowing apps to capture sensitive information such as passwords or personal messages.

Remediation

Users can update to iOS 18.7, iPadOS 18.7, iOS 26, or iPadOS 26 to address this vulnerability.

Added: Sep 15, 2025, 11:22 PM
Updated: Sep 15, 2025, 11:22 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
3.3
remediation
7.7
relevance
0.5
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.