CVE-2025-30426

This issue was addressed with additional entitlement checks. This issue is fixed in visionOS 2.4, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to enumerate a user's installed apps.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*

History

07 Apr 2025, 14:02

Type Values Removed Values Added
Summary
  • (es) Este problema se solucionó con comprobaciones adicionales de derechos. Este problema está corregido en visionOS 2.4, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 y iPadOS 18.4, y macOS Sequoia 15.4. Una aplicación puede enumerar las aplicaciones instaladas de un usuario.
CPE cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
First Time Apple iphone Os
Apple
Apple tvos
Apple visionos
Apple ipados
Apple macos
References () https://support.apple.com/en-us/122371 - () https://support.apple.com/en-us/122371 - Vendor Advisory
References () https://support.apple.com/en-us/122372 - () https://support.apple.com/en-us/122372 - Vendor Advisory
References () https://support.apple.com/en-us/122373 - () https://support.apple.com/en-us/122373 - Vendor Advisory
References () https://support.apple.com/en-us/122377 - () https://support.apple.com/en-us/122377 - Vendor Advisory
References () https://support.apple.com/en-us/122378 - () https://support.apple.com/en-us/122378 - Vendor Advisory

01 Apr 2025, 05:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-200

31 Mar 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-31 23:15

Updated : 2025-04-07 14:02


NVD link : CVE-2025-30426

Mitre link : CVE-2025-30426

CVE.ORG link : CVE-2025-30426


JSON object : View

Products Affected

apple

  • macos
  • visionos
  • tvos
  • ipados
  • iphone_os
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor