Impact
A privacy issue was reported wherein the logging of text field contents was not properly restricted, allowing an application to read sensitive user data. The flaw falls under Improper Access Control, enabling apps to read data that should be private.
Affected Systems
Apple devices running iOS 18.4 or earlier, iPadOS 18.4 or earlier, macOS Sequoia 15.4 or earlier, tvOS 18.4 or earlier, visionOS 2.4 or earlier, and watchOS 11.4 or earlier are affected. The issue persists until the respective operating system updates are applied.
Risk and Exploitability
The CVSS score of 5.5 ranks the vulnerability as moderate. The EPSS score of less than 1% indicates a very low probability of exploitation at the time of this analysis, and the vulnerability is not listed in CISA's KEV catalog. Based on the description, the likely attack vector is that a malicious or compromised application executing on the device can access text field contents locally, potentially exposing personal information to unintended parties.
OpenCVE Enrichment
EUVD