Impact
The vulnerability involves incomplete redaction of private data in system log entries. As a result, an application may be able to read logs that contain sensitive user information, leading to potential privacy violations and unauthorized disclosure of personal data.
Affected Systems
Apple macOS is affected, with the issue fixed in macOS Tahoe 26. All earlier releases are potentially susceptible to this privacy flaw.
Risk and Exploitability
The CVSS score of 6.2 indicates a moderate overall risk and the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in CISA KEV. The likely attack vector involves a local application that can access system logs; the attacker would need the ability to run software on the target machine to read logs containing unsanitized user data. The impact is limited to privacy breach rather than system compromise.
OpenCVE Enrichment
EUVD