Apple Products Crash Reporter Privacy Vulnerability Allowing App Enumeration of Installed Apps

Vulnerability

A privacy vulnerability has been identified in the Crash Reporter component of various Apple operating systems, including iOS 18.7.7, iPadOS 18.7.7, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, and watchOS 26.4. This vulnerability allows apps to enumerate a user's installed applications. The issue arises from the Crash Reporter component inadvertently exposing information about installed apps, potentially leading to unauthorized app enumeration.

Impact

Exploitation of this vulnerability could result in unauthorized access to information about the user's installed applications, allowing an app to enumerate all apps installed on the device.

Remediation

Users can update to the latest versions of iOS, iPadOS, macOS, tvOS, visionOS, and watchOS to address this vulnerability. Instructions for updating can be found on the Apple Support website.

Added: Mar 25, 2026, 1:37 AM
Updated: Mar 25, 2026, 1:37 AM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
3.3
remediation
7.7
relevance
4.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.