VYPR
Unrated severityNVD Advisory· Published Feb 21, 2024· Updated Nov 4, 2025

CVE-2023-42878

CVE-2023-42878

Description

A privacy issue in Apple OSes allows an app to access sensitive user data due to insufficient log data redaction, fixed in October 2023 updates.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A privacy issue in Apple OSes allows an app to access sensitive user data due to insufficient log data redaction, fixed in October 2023 updates.

Vulnerability

A privacy issue exists in the logging subsystems of Apple watchOS (before 10.1), macOS Sonoma (before 14.1), iOS (before 17.1), and iPadOS (before 17.1) [1][2][3]. The vulnerability stems from insufficient private data redaction in log entries, potentially allowing an app to read sensitive user data that was inadvertently written to system logs [1][2][3]. No specific configuration or user interaction is required to reach the affected code path beyond the app having access to system log entries.

Exploitation

An attacker would need to deploy a malicious app on a vulnerable device, as the app simply needs the ability to read system logs, a common permission granted to many iOS and macOS applications [1][2][3]. No additional network position or authentication beyond normal app installation is required. The attacker does not need to trigger a specific sequence of user actions; the vulnerability is present whenever system logging occurs with insufficient redaction.

Impact

A successful exploit allows the app to access sensitive user data that was logged without proper redaction [1][2][3]. This constitutes a confidentiality breach, as the attacker could obtain private information such as credentials, personal details, or other sensitive data depending on what the systems logged. No code execution or privilege escalation is described in the references; the impact is limited to information disclosure.

Mitigation

Apple addressed the issue with improved private data redaction for log entries in watchOS 10.1, macOS Sonoma 14.1, iOS 17.1, and iPadOS 17.1, released October 25, 2023 [1][2][3]. Users should update their devices to the latest available OS versions via the Software Update mechanism. No workarounds or KEV listing are mentioned in the available references. For devices that cannot update, no mitigation is provided.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

7

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.