PT-2025-5330 · Apple · Macos Sequoia+2

·

CVE-2025-24169

·

Published

2025-01-27

·

Updated

2026-07-18

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Safari versions prior to 18.3 macOS Sequoia versions prior to 15.3
Description A logging issue exists where insufficient data redaction in registration log files allows for information disclosure. A malicious application can exploit this to bypass browser extension authentication and enumerate a user's saved account data within the Passwords component, bypassing TCC (Transparency, Consent, and Control) protections.
Recommendations Update Safari to version 18.3. Update macOS Sequoia to version 15.3.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01361
CVE-2025-24169

Affected Products

Apple Macos
Safari
Macos Sequoia