CVE Vulnerabilities

CVE-2025-31213

Insertion of Sensitive Information into Log File

Published: May 12, 2025 | Modified: May 27, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A logging issue was addressed with improved data redaction. This issue is fixed in iPadOS 17.7.7, macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An app may be able to access associated usernames and websites in a users iCloud Keychain.

Weakness

The product writes sensitive information to a log file.

Affected Software

Name Vendor Start Version End Version
Ipados Apple * 17.7.7 (excluding)
Macos Apple * 13.7.6 (excluding)
Macos Apple 14.0 (including) 14.7.6 (excluding)
Macos Apple 15.0 (including) 15.5 (excluding)

Potential Mitigations

References