rootpwn

medium · CVSS v3 6.5

CVE-2026-82985

A logic flaw in the Photos app's filter-based smart albums causes file listings to evaluate against the viewing user's search configuration

Overview

A logic flaw in the Photos app's filter-based smart albums causes file listings to evaluate against the viewing user's search configuration rather than the owner's. This misattribution leads to unintended metadata disclosure when a smart album is shared. Defenders must address this information exposure vulnerability to prevent unauthorized file discovery.

Description

The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user viewing the album, rather than the album owner's configuration. When an album owner shares a smart album with another user, that user's own folder configuration is used to determine which of the owner's files are searched — allowing them to discover files (name, file ID, and other metadata) in folders the album owner never intended to include in the shared album. This requires the album owner to have shared a filter-based smart album with the attacker; it does not allow access to arbitrary users' files without such a share.

Impact

The vulnerability results in an unauthorized information disclosure of file names, file IDs, and associated metadata. It affects privacy boundaries within shared smart albums where the viewing user's folder configuration overrides intended sharing scopes. The confidentiality of shared assets is compromised, though integrity and availability remain unaffected. Only users who have been explicitly granted access to a shared smart album can exploit this condition.

Remediation

Apply the latest security updates provided by the vendor for the Photos app. Audit existing shared smart albums to ensure sensitive folders are not inadvertently exposed. Review and enforce strict principle of least privilege regarding file sharing permissions.

Risk context

Rated as medium severity with a CVSS v3 score of 6.5, representing a moderate risk to data confidentiality. EPSS data is not currently available for this identifier. Mitigation should be prioritized during regular patch cycles.

Affected products

  • Photos app

Scores

Severity
medium
CVSS v2
6.8
CVSS v3
6.5
CVSS v4
EPSS

information-disclosure access-control photos-app logic-flaw shared-albums

← All CVEs