Impact
A flaw in macOS Messages causes contact information to be written unredacted to system logs when a conversation is deleted. The vulnerability satisfies CWE-200 (Information Exposure), and a user who initiates a delete can inadvertently cause the system to record recoverable personal data. The impact is a confidentiality breach that could expose user contact details without the user’s consent. The CVSS score of 9.8 underscores the severity of the potential information loss, though no remote code execution or denial‑of‑service is involved.
Affected Systems
Apple macOS is affected. The issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, and macOS Ventura 13.7.3, so any builds prior to those versions are vulnerable. Consequently, systems running macOS Sequoia 15.2 or earlier, Sonoma 14.7.2 or earlier, or Ventura 13.7.2 or earlier are at risk.
Risk and Exploitability
The CVSS score of 9.8 signals an extremely high severity, while the EPSS score of less than 1% indicates that widespread exploitation is unlikely at present. Based on the description, it is inferred that the flaw is local and requires an authenticated user to delete a conversation, but once this action is performed, the data is logged in a way that could be accessed by any account with privileges to read system logs. The vulnerability is not listed in the CISA KEV catalog, suggesting that no known exploits are actively used in the wild.
OpenCVE Enrichment
EUVD