VulnerabilityModified
CVE-2025-24214
A privacy issue was addressed by not logging contents of text fields.
MEDIUM 5.5EPSS 0.28%
Does this matter?
Lower severity and a low EPSS score (0.28%). Track it; it rarely justifies an emergency change on its own.
Description
A privacy issue was addressed by not logging contents of text fields. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to access sensitive user data.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 0.28% probability · 21th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- apple/ipados · apple/iphone os · apple/macos · apple/tvos · apple/visionos
- Source
- product-security@apple.com
References
- https://support.apple.com/en-us/122371Vendor Advisory
- https://support.apple.com/en-us/122373Vendor Advisory
- https://support.apple.com/en-us/122376
- https://support.apple.com/en-us/122377Vendor Advisory
- https://support.apple.com/en-us/122378Vendor Advisory
- http://seclists.org/fulldisclosure/2025/Apr/11
- http://seclists.org/fulldisclosure/2025/Apr/12
- http://seclists.org/fulldisclosure/2025/Apr/13
- http://seclists.org/fulldisclosure/2025/Apr/4
- http://seclists.org/fulldisclosure/2025/Apr/8
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.