VulnerabilityModified
CVE-2025-24217
This issue was addressed with improved redaction of sensitive information.
MEDIUM 5.5EPSS 0.28%
Does this matter?
Lower severity and a low EPSS score (0.28%). Track it; it rarely justifies an emergency change on its own.
Description
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, watchOS 11.4. An app may be able to access sensitive user data.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.28% probability · 20th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- apple/ipados · apple/iphone os · apple/macos · apple/tvos
- Source
- product-security@apple.com
References
- https://support.apple.com/en-us/122371Vendor Advisory
- https://support.apple.com/en-us/122373Vendor Advisory
- https://support.apple.com/en-us/122376
- https://support.apple.com/en-us/122377Vendor Advisory
- http://seclists.org/fulldisclosure/2025/Apr/11
- http://seclists.org/fulldisclosure/2025/Apr/13
- http://seclists.org/fulldisclosure/2025/Apr/4
- http://seclists.org/fulldisclosure/2025/Apr/8
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.