VYPR
Medium severity5.5NVD Advisory· Published Mar 31, 2025· Updated Apr 2, 2026

CVE-2025-30447

CVE-2025-30447

Description

The issue was resolved by sanitizing logging. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to access sensitive user data.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A logging issue in Apple operating systems fails to redact sensitive data, potentially allowing an app to access it; fixed in multiple platform updates.

CVE-2025-30447 is a vulnerability in Apple's operating systems due to a logging issue where sensitive user data is not properly redacted from logs. This issue affects iOS, iPadOS, macOS, tvOS, visionOS, and watchOS versions prior to the fixes released on March 31, 2025 [2][4].

An app running on the device may be able to access these logs, thereby gaining access to sensitive user data. The exploitation requires the app to be installed and executed on the device, but no special privileges beyond normal app sandbox are needed. The vulnerability is present in logging mechanisms that fail to redact sensitive information.

The impact is that an attacker with an app on the device could extract sensitive user data, such as personal information or credentials, from log entries. This could lead to privacy breaches or further compromise.

Apple has addressed the issue by improving data redaction in logging. The fixes are included in iOS 18.4, iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, and watchOS 11.4 [2][4]. Users are advised to update to the latest versions.

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

5

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

16

News mentions

0

No linked articles in our index yet.