VulnerabilityModified
CVE-2025-24117
This issue was addressed with improved redaction of sensitive information.
MEDIUM 5.5EPSS 0.27%
Does this matter?
Lower severity and a low EPSS score (0.27%). Track it; it rarely justifies an emergency change on its own.
Description
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, visionOS 2.3, watchOS 11.3. An app may be able to fingerprint the user.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 0.27% probability · 19th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-922
- Affected
- apple/ipados · apple/iphone os · apple/macos · apple/visionos · apple/watchos
- Source
- product-security@apple.com
References
- https://support.apple.com/en-us/122066Release Notes, Vendor Advisory
- https://support.apple.com/en-us/122067Release Notes, Vendor Advisory
- https://support.apple.com/en-us/122068Release Notes, Vendor Advisory
- https://support.apple.com/en-us/122071Release Notes, Vendor Advisory
- https://support.apple.com/en-us/122073Release Notes, Vendor Advisory
- http://seclists.org/fulldisclosure/2025/Jan/12
- http://seclists.org/fulldisclosure/2025/Jan/14
- http://seclists.org/fulldisclosure/2025/Jan/15
- http://seclists.org/fulldisclosure/2025/Jan/18
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.