Impact
A logging flaw that prevented proper redaction of user data was identified. An application can read credentials, personal identifiers, or other confidential data from system logs, effectively exposing sensitive information.
Affected Systems
Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are all affected. Fixed versions include iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27. Devices running earlier releases remain vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need local access to an application capable of reading system logs; once logged data is accessed, the application can read sensitive user information that was not properly redacted. Because the exploitation requires an existing app with sufficient permissions, the overall risk is moderate, but any device running an earlier release should apply the patch to eliminate the exposure.
OpenCVE Enrichment