Impact
A logging issue existed in Apple operating systems that allowed sensitive personal data to be recorded without sufficient redaction. The flaw could enable a malicious application to read log files that contain private information, leading to a confidentiality breach. This type of weakness aligns with CWE-532, which describes excessive logging that fails to protect temporary data.
Affected Systems
The issue affected multiple Apple platforms, including iOS, iPadOS, macOS (Sequoia and Sonoma), and visionOS. Systems running versions prior to iOS 18.4, iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.8.2, or visionOS 2.4 were vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity vulnerability, while the EPSS score of less than 1% suggests a low probability of exploitation and the vulnerability is not listed in the CISA KEV catalog. Attackers would likely need to install or trick a user into installing a malicious application that can read system logs, requiring local execution. The remediation consists of applying the official OS updates, which eliminates the risk.
OpenCVE Enrichment
EUVD