Apple Photos Smart Album Info Disclosure via Search Config
CVE-2026-82985 Published on September 18, 2026

The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user viewing the album, rather than the album owner's configuration. When an album owner shares a smart album with another user, that user's own folder configuration is used to determine which of the owner's files are searched allowing them to discover files (name, file ID, and other metadata) in folders the album owner never intended to include in the shared album. This requires the album owner to have shared a filter-based smart album with the attacker; it does not allow access to arbitrary users' files without such a share.

NVD

Weakness Type

What is an Authorization Vulnerability?

The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVE-2026-82985 has been classified to as an Authorization vulnerability or weakness.


Products Associated with CVE-2026-82985

Want to know whenever a new CVE is published for Nextcloud Server? stack.watch will email you.

 

Affected Versions

Nextcloud Server: