Privacy Issue in Apple's iOS and macOS Products
CVE-2023-40437
5.5MEDIUM
Summary
A recently identified privacy issue in Apple's iOS and macOS platforms raises concerns regarding the handling of sensitive location data in log entries. This vulnerability can potentially allow unauthorized applications to access private data, posing risks to user privacy. Apple has addressed this issue in the latest updates for iOS 16.6, iPadOS 16.6, and macOS Ventura 13.5, implementing improved measures for the redaction of sensitive information in logs. Users are encouraged to update their devices promptly to mitigate potential threats.
Affected Version(s)
iOS and iPadOS < 16.6
macOS < 13.5
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved