CVE-2025-30426

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 31, 2025
Updated: Apr 7, 2025
CWE ID 200

Summary

CVE-2025-30426 is a vulnerability that affected multiple Apple operating systems, including visionOS, tvOS, iPadOS, iOS, and macOS Sequoia. This issue allowed a malicious app to access a user's list of installed apps, bypassing necessary entitlement checks. Apple addressed this security flaw with additional verification procedures in the aforementioned software updates: visionOS 2.4, tvOS 18.4, iPadOS 17.7.6, iOS 18.4, and iPadOS 18.4. Users are strongly encouraged to install these patches to secure their devices against this potential privacy risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share