Impact
A logging defect prevented proper redaction of sensitive data within system logs. The flaw allows an application to read information that should not be exposed, potentially leaking user credentials or personal data. This weakness is categorized as CWE‑532 and carries a CVSS score of 5.5, indicating moderate severity
Affected Systems
The issue affects Apple devices running iPadOS and macOS prior to the release of iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, or macOS Ventura 13.7.7. Upgrading to any of those versions removes the vulnerability.
Risk and Exploitability
The EPSS score is less than 1%, suggesting low exploitation probability. The vulnerability appears to require local execution or the presence of an application that can read system logs, so the attack vector is most likely local or app-based. It is not listed in the CISA KEV catalog.
OpenCVE Enrichment
EUVD