
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28882 is an information disclosure vulnerability in Apple's libxpc component that allows a locally installed app to enumerate a user's installed applications without authorization. The issue stems from insufficient validation checks within the XPC inter-process communication subsystem. It affects iOS and iPadOS (prior to 26.4 and 18.7.9), macOS Tahoe (prior to 26.4), tvOS (prior to 26.4), visionOS (prior to 26.4), and watchOS (prior to 26.4). Apple disclosed and patched the vulnerability on March 24, 2026, with an additional update released May 11, 2026. It carries a CVSS v3.1 base score of 4.0 (Medium) (Apple iOS/iPadOS Advisory, Apple macOS Advisory).
The vulnerability resides in Apple's libxpc library, which underpins the XPC inter-process communication framework used across all Apple operating systems. Insufficient validation checks (broadly classifiable as CWE-200: Exposure of Sensitive Information to an Unauthorized Actor) allowed a locally running app to query or observe XPC service interactions in a way that revealed which other applications were installed on the device. Exploitation requires only local app execution — no elevated privileges or user interaction are needed. The vulnerability was discovered and reported by Ilya Andr (andrd3v), Ilias Morad (A2nkF) of Voynich Group, Duy Trần (@khanhduytran0), and @hugeBlack (Apple iOS/iPadOS Advisory, Apple macOS Advisory).
Successful exploitation allows a sandboxed app running locally on the device to enumerate the full list of applications installed by the user, constituting a confidentiality breach with no impact on integrity or availability. This information can be leveraged for user profiling, targeted social engineering, or fingerprinting — for example, identifying the presence of security tools, banking apps, or sensitive productivity software. While the direct impact is limited to information disclosure, the enumerated data could facilitate more sophisticated follow-on attacks (Apple iOS/iPadOS Advisory, Feedly Intelligence).
Apple has released patches addressing CVE-2026-28882 across all affected platforms. Users and administrators should update to the following versions or later: iOS 26.4 or iOS 18.7.9, iPadOS 26.4 or iPadOS 18.7.9, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, and watchOS 26.4. An additional update was released on May 11, 2026, which also includes this fix. No configuration-based workarounds are available; patching is the only remediation. Organizations should prioritize updating all managed Apple devices, and consider implementing app vetting procedures to limit exposure from untrusted applications (Apple iOS/iPadOS Advisory, Apple macOS Advisory, Apple May Update).
The vulnerability was covered as part of Apple's broader March 2026 security update, which addressed over 140 vulnerabilities across Apple platforms. Security aggregators such as SANS ISC and BeyondMachines noted the scale of the update, though CVE-2026-28882 itself did not attract significant individual commentary given its medium severity and lack of active exploitation (SANS ISC, BeyondMachines). CIS also published an advisory noting multiple vulnerabilities in Apple products from this update cycle (CIS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."