VYPR
Unrated severityNVD Advisory· Published Jun 23, 2023· Updated Dec 5, 2024

CVE-2023-28191

CVE-2023-28191

Description

An app may bypass Privacy preferences by accessing log entries with insufficient redaction in Apple OSes.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An app may bypass Privacy preferences by accessing log entries with insufficient redaction in Apple OSes.

Vulnerability

A privacy vulnerability exists in Apple's operating systems where log entries may contain sensitive data that is not properly redacted, allowing an app to bypass Privacy preferences. This affects watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5, and iPadOS 16.5 [1][2][3][4].

Exploitation

An attacker would need to have an app installed on the device. The app could access log entries that inadvertently contain private information due to insufficient redaction. No special user interaction beyond installing the app is required, and no additional privileges are needed beyond normal app sandbox restrictions [1][2].

Impact

A malicious app could gain access to sensitive information that should be protected by Privacy preferences, such as location, contacts, or other private data. This could lead to disclosure of private information without user consent [1][2].

Mitigation

Apple has released patches in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5, and iPadOS 16.5 on May 18, 2023. Users should update their devices to the latest available versions [1][2][3][4]. There are no known workarounds; updating is the recommended mitigation.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

11

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

6

News mentions

0

No linked articles in our index yet.