PT-2025-5330 · Apple · Macos Sequoia+2
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Safari versions prior to 18.3
macOS Sequoia versions prior to 15.3
Description
A logging issue exists where insufficient data redaction in registration log files allows for information disclosure. A malicious application can exploit this to bypass browser extension authentication and enumerate a user's saved account data within the Passwords component, bypassing TCC (Transparency, Consent, and Control) protections.
Recommendations
Update Safari to version 18.3.
Update macOS Sequoia to version 15.3.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apple Macos
Safari
Macos Sequoia