Description
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, watchOS 26.3. A user may be able to view sensitive user information.
Published: 2026-02-11
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive information exposure
Action: Patch Update
AI Analysis

Impact

A logging flaw that allows a user to read private data that should have been redacted. The defect impacts the handling of log entries on Apple operating systems, enabling disclosure of potentially confidential user information. The flaw is identified as a failure to redact data correctly, a weakness that falls under CWE‑377.

Affected Systems

Apple's iOS, iPadOS, macOS, tvOS and watchOS are affected. The issue was corrected in the 26.3 releases of each platform: iOS 26.3, iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3 and watchOS 26.3. Systems running earlier builds are susceptible.

Risk and Exploitability

The CVSS base score is 5.5, indicating moderate severity. EPSS indicates a very low exploitation probability (<1 %). The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local; a legitimate user with access to the device could trigger the logging path that unintentionally reveals sensitive data. Patch availability reduces the risk to zero once updated.

Generated by OpenCVE AI on April 15, 2026 at 20:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update all affected devices to iOS 26.3, iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3 or watchOS 26.3 or later.
  • Ensure all operating system updates are installed across the fleet to eliminate exposure.
  • If an upgrade is not immediately possible, restrict or disable logging of sensitive data to prevent accidental disclosure.

Generated by OpenCVE AI on April 15, 2026 at 20:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Apr 2026 21:15:00 +0000

Type Values Removed Values Added
Title Logging Issue Exposes Sensitive User Information

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description A logging issue was addressed with improved data redaction. This issue is fixed in watchOS 26.3, iOS 26.3 and iPadOS 26.3, tvOS 26.3, macOS Tahoe 26.3. A user may be able to view sensitive user information. A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, watchOS 26.3. A user may be able to view sensitive user information.

Fri, 13 Feb 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-377
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Fri, 13 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Thu, 12 Feb 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple watchos

Wed, 11 Feb 2026 23:15:00 +0000

Type Values Removed Values Added
Description A logging issue was addressed with improved data redaction. This issue is fixed in watchOS 26.3, iOS 26.3 and iPadOS 26.3, tvOS 26.3, macOS Tahoe 26.3. A user may be able to view sensitive user information.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:24:30.707Z

Reserved: 2025-11-11T14:43:07.863Z

Link: CVE-2026-20649

cve-icon Vulnrichment

Updated: 2026-02-13T17:14:23.259Z

cve-icon NVD

Status : Modified

Published: 2026-02-11T23:16:07.823

Modified: 2026-04-02T19:21:17.257

Link: CVE-2026-20649

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-15T21:00:09Z

Weaknesses