CVE Vulnerabilities

CVE-2025-24117

Insecure Storage of Sensitive Information

Published: Jan 27, 2025 | Modified: Nov 03, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iPadOS 17.7.4, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3. An app may be able to fingerprint the user.

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

Affected Software

NameVendorStart VersionEnd Version
IpadosApple*17.7.4 (excluding)
IpadosApple18.0 (including)18.3 (excluding)
Iphone_osApple*18.3 (excluding)
MacosApple*15.3 (excluding)
VisionosApple*2.3 (excluding)
WatchosApple*11.3 (excluding)

References