CVE Vulnerabilities

CVE-2025-24117

Insecure Storage of Sensitive Information

Published: Jan 27, 2025 | Modified: Jan 31, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iPadOS 17.7.4, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3. An app may be able to fingerprint the user.

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Ipados Apple * 17.7.4 (excluding)
Ipados Apple 18.0 (including) 18.3 (excluding)
Iphone_os Apple * 18.3 (excluding)
Macos Apple * 15.3 (excluding)
Visionos Apple * 2.3 (excluding)
Watchos Apple * 11.3 (excluding)

References