VYPR
Unrated severityNVD Advisory· Published Mar 8, 2024· Updated Nov 4, 2025

CVE-2023-28826

CVE-2023-28826

Description

An app on Apple platforms may bypass redaction and access sensitive user data due to a logic issue addressed in iOS, iPadOS, and macOS updates.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An app on Apple platforms may bypass redaction and access sensitive user data due to a logic issue addressed in iOS, iPadOS, and macOS updates.

Vulnerability

A logic issue in the redaction mechanism of multiple Apple operating systems allowed an application to access sensitive user data that should have been obscured. The vulnerability is present in iOS 16.7.6 and iPadOS 16.7.6, macOS Monterey 12.7.4, macOS Sonoma 14.1, and macOS Ventura 13.6.5 [1][3][4]. The exact component is not disclosed by Apple, but the flaw resides in how sensitive information is redacted when an app interacts with system data.

Exploitation

An attacker must distribute or trick the user into running a malicious app on an affected device. No special network position or elevated privileges are required beyond the ability to install and execute an app. The app can then access system redacted data without proper authorization.

Impact

Successful exploitation allows a malicious app to access sensitive user data, such as personal information or credentials, that the system intended to protect. The compromise affects confidentiality, potentially leading to further privacy breaches.

Mitigation

Apple has released fixes in iOS 16.7.6 and iPadOS 16.7.6 (available for supported devices), macOS Monterey 12.7.4, macOS Sonoma 14.1, and macOS Ventura 13.6.5. Users should update their devices to the latest available version. No workarounds are provided.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

7

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.