Description
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to access sensitive user data.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive data exposure via improperly redacted logs
Action: Patch Immediately
AI Analysis

Impact

A logging flaw that prevented proper redaction of user data was identified. An application can read credentials, personal identifiers, or other confidential data from system logs, effectively exposing sensitive information.

Affected Systems

Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are all affected. Fixed versions include iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27. Devices running earlier releases remain vulnerable.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need local access to an application capable of reading system logs; once logged data is accessed, the application can read sensitive user information that was not properly redacted. Because the exploitation requires an existing app with sufficient permissions, the overall risk is moderate, but any device running an earlier release should apply the patch to eliminate the exposure.

Generated by OpenCVE AI on September 20, 2026 at 20:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade all affected Apple devices to the OS releases that contain the fix, such as iOS 27, macOS 27, and the corresponding versions for iPadOS, tvOS, visionOS, and watchOS.
  • If a device update cannot be performed immediately, apply device‑management policies that block or limit third‑party application access to system logs and enforce strict redaction rules for any user data logged.
  • Review or update your applications to guarantee that they do not write unredacted sensitive data to system logs; enable any built‑in log redaction features and clear existing logs to remove exposed information.

Generated by OpenCVE AI on September 20, 2026 at 20:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Title Improper Log Redaction Exposes Sensitive User Data

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-532
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Data Exposure via Improper Log Redaction
Weaknesses CWE-200

Tue, 15 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Title Data Exposure via Improper Log Redaction
Weaknesses CWE-200

Tue, 15 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A logging issue was addressed with improved data redaction. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to access sensitive user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T15:52:45.855Z

Reserved: 2026-09-01T21:13:17.749Z

Link: CVE-2026-84527

cve-icon Vulnrichment

Updated: 2026-09-17T15:51:34.366Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:29.310

Modified: 2026-09-18T17:21:00.510

Link: CVE-2026-84527

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:30:05Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File