CVE Vulnerabilities

CVE-2024-44239

Insertion of Sensitive Information into Log File

Published: Oct 28, 2024 | Modified: Nov 03, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An information disclosure issue was addressed with improved private data redaction for log entries. This issue is fixed in tvOS 18.1, iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, macOS Ventura 13.7.1, macOS Sonoma 14.7.1, watchOS 11.1, visionOS 2.1. An app may be able to leak sensitive kernel state.

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
IpadosApple*17.7.1 (excluding)
IpadosApple18.0 (including)18.0 (including)
Iphone_osApple*17.7.1 (excluding)
Iphone_osApple18.0 (including)18.0 (including)
MacosApple*13.7.1 (excluding)
MacosApple14.0 (including)14.7.1 (excluding)
TvosApple*18.1 (excluding)
VisionosApple*2.1 (excluding)
WatchosApple*11.1 (excluding)

Potential Mitigations

References