Impact
Apple macOS suffers from a privacy issue that allows an application to access and potentially expose sensitive user data through insufficient log redaction. The vulnerability falls under CWE‑200, indicating an information‑leak risk. If exploited, confidential data could be read from system logs, compromising user privacy and confidentiality.
Affected Systems
The flaw is present in macOS versions prior to Sequoia 15.5, Sonoma 14.7.6, and Ventura 13.7.6. Those three macOS releases contain the fix; any earlier releases remain vulnerable.
Risk and Exploitability
The CVSS score of 5.5 reflects moderate impact; the EPSS score of less than 1% suggests a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a malicious or compromised application that gains the ability to read system logs, as the flaw involves inadequate redaction of private data within those logs.
OpenCVE Enrichment
EUVD