CVE-2025-30426

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
31/03/2025
Last modified:
07/04/2025

Description

This issue was addressed with additional entitlement checks. This issue is fixed in visionOS 2.4, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to enumerate a user's installed apps.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* 17.7.6 (excluding)
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* 18.0 (including) 18.4 (excluding)
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* 18.4 (excluding)
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* 15.0 (including) 15.4 (excluding)
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* 18.4 (excluding)
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:* 2.4 (excluding)