THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-q9c5-pp7m-fm2g (medium) — Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs

[GHSA] GHSA-q9c5-pp7m-fm2g (medium) — Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs

highgithub_advisoriesPublished 2026-08-20

GHSA-q9c5-pp7m-fm2g Severity: medium CVE: None

Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs

### Summary

Two endpoints serving in-house iOS application packages and manifests in Fleet's enterprise tier are reachable without a hard-to-guess token in the URL, allowing an unauthenticated attacker who can reach the Fleet server to download an in-house IPA by gues

Indicators of compromise

Original source: https://github.com/advisories/GHSA-q9c5-pp7m-fm2g