Impact
A logging flaw in macOS allowed unredacted user‑sensitive data to be written to logs. The vulnerability was mitigated by improving data redaction in newer releases, but prior versions risk exposing confidential information. This flaw falls under Information Exposure weaknesses.
Affected Systems
Apple’s macOS is affected. The issue was fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. Versions prior to these contain the vulnerable logging logic and may leak private data through log files.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and the EPSS score is less than 1% with no listing in the CISA KEV catalog, suggesting limited public exploitation. Based on the description, it is inferred that a local or privileged application that can read system logs might be able to exploit the flaw to obtain sensitive user data. The absence of a documented exploit does not eliminate the risk of data exposure, particularly in environments where internal threat actors have access to user machines.
OpenCVE Enrichment