Insecure Storage of Sensitive Information
CVE-2024-44298
Summary
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.1. An app may be able to access information about a user's contacts.
- LOW
- LOCAL
- NONE
- UNCHANGED
- REQUIRED
- NONE
- LOW
- NONE
CWE-922 - Insecure Storage of Sensitive Information
The software stores sensitive information without properly limiting read or write access by unauthorized actors.
References
Advisory Timeline
- Published