Impact
The vulnerability stems from a logging flaw that allowed sensitive user data to be captured in system logs before the OS could apply proper redaction, potentially exposing personally identifiable information that should remain concealed, creating risk of inadvertent data leakage. The weakness is classified as CWE-532, indicating improper handling of log data that can lead to data exposure.
Affected Systems
Affected systems include Apple’s mobile and desktop operating systems: iOS, iPadOS, and macOS. All releases prior to the 26.1 point update for each platform are at risk, as the fix adds enhanced data redaction to logs. The update versions iOS 26.1, iPadOS 26.1, and macOS 26.1 incorporate the remedial changes.
Risk and Exploitability
The CVSS score of 5.5 signals a moderate risk, while the EPSS score of less than 1% indicates a very low likelihood of exploitation. The likely attack vector is local device access or a privileged application to read unredacted logs. With this premise, remote exploitation appears unlikely given the current metrics. Successful exploitation could lead to personal data leakage for the affected user.
OpenCVE Enrichment