medium · CVSS v3 6.5
CVE-2026-82985
A logic flaw in the Photos app's filter-based smart albums causes file listings to evaluate against the viewing user's search configuration
Overview
A logic flaw in the Photos app's filter-based smart albums causes file listings to evaluate against the viewing user's search configuration rather than the owner's. This misattribution leads to unintended metadata disclosure when a smart album is shared. Defenders must address this information exposure vulnerability to prevent unauthorized file discovery.
Description
The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user viewing the album, rather than the album owner's configuration. When an album owner shares a smart album with another user, that user's own folder configuration is used to determine which of the owner's files are searched — allowing them to discover files (name, file ID, and other metadata) in folders the album owner never intended to include in the shared album. This requires the album owner to have shared a filter-based smart album with the attacker; it does not allow access to arbitrary users' files without such a share.
Impact
The vulnerability results in an unauthorized information disclosure of file names, file IDs, and associated metadata. It affects privacy boundaries within shared smart albums where the viewing user's folder configuration overrides intended sharing scopes. The confidentiality of shared assets is compromised, though integrity and availability remain unaffected. Only users who have been explicitly granted access to a shared smart album can exploit this condition.
Remediation
Apply the latest security updates provided by the vendor for the Photos app. Audit existing shared smart albums to ensure sensitive folders are not inadvertently exposed. Review and enforce strict principle of least privilege regarding file sharing permissions.
Risk context
Rated as medium severity with a CVSS v3 score of 6.5, representing a moderate risk to data confidentiality. EPSS data is not currently available for this identifier. Mitigation should be prioritized during regular patch cycles.
Affected products
- Photos app
Scores
- Severity
- medium
- CVSS v2
- 6.8
- CVSS v3
- 6.5
- CVSS v4
- —
- EPSS
- —