CVE-2026-28833

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. An app may be able to enumerate a user's installed apps.
References
Link Resource
https://support.apple.com/en-us/126792 Release Notes Vendor Advisory
https://support.apple.com/en-us/126794 Release Notes Vendor Advisory
https://support.apple.com/en-us/126799 Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*

History

10 May 2026, 14:16

Type Values Removed Values Added
CWE CWE-284
Summary
  • (es) Se abordó un problema de permisos con restricciones adicionales. Este problema está corregido en iOS 26.4 y iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Una aplicación podría enumerar las aplicaciones instaladas de un usuario.

25 Mar 2026, 18:25

Type Values Removed Values Added
CWE NVD-CWE-noinfo
References () https://support.apple.com/en-us/126792 - () https://support.apple.com/en-us/126792 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/126794 - () https://support.apple.com/en-us/126794 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/126799 - () https://support.apple.com/en-us/126799 - Release Notes, Vendor Advisory
CPE cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
First Time Apple iphone Os
Apple visionos
Apple ipados
Apple
Apple macos

25 Mar 2026, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.2

25 Mar 2026, 01:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-25 01:17

Updated : 2026-05-10 14:16


NVD link : CVE-2026-28833

Mitre link : CVE-2026-28833

CVE.ORG link : CVE-2026-28833


JSON object : View

Products Affected

apple

  • ipados
  • visionos
  • macos
  • iphone_os
CWE
NVD-CWE-noinfo CWE-284

Improper Access Control