Impact
A logging flaw that allows a user to read private data that should have been redacted. The defect impacts the handling of log entries on Apple operating systems, enabling disclosure of potentially confidential user information. The flaw is identified as a failure to redact data correctly, a weakness that falls under CWE‑377.
Affected Systems
Apple's iOS, iPadOS, macOS, tvOS and watchOS are affected. The issue was corrected in the 26.3 releases of each platform: iOS 26.3, iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3 and watchOS 26.3. Systems running earlier builds are susceptible.
Risk and Exploitability
The CVSS base score is 5.5, indicating moderate severity. EPSS indicates a very low exploitation probability (<1 %). The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local; a legitimate user with access to the device could trigger the logging path that unintentionally reveals sensitive data. Patch availability reduces the risk to zero once updated.
OpenCVE Enrichment