Impact
A logging component in Apple macOS fails to fully redact sensitive user information, leaving private data in plain text within system logs. This flaw represents an improper access control weakness and aligns with CWE‑284. If an application can read those logs, it may retrieve personal data, thereby compromising the confidentiality of the affected user.
Affected Systems
Apple macOS releases before the security update that includes Sequoia 15.7.5, Sonoma 14.8.5, or Tahoe 26.4 are potentially impacted. All Apple‑hardware running these earlier macOS versions may expose logs that contain unredacted personal information.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS is reported below 1 %, and the vulnerability is not listed in CISA’s KEV catalog, suggesting a lower likelihood of active exploitation. The description states that an app may access sensitive data; the likely attack vector is a locally privileged or system‑level application that can read log files, inferred from the mention of app access. No additional prerequisites are specified.
OpenCVE Enrichment