CVE-2026-20619
Sensitive Data Exposure via Logging Flaw in macOS Sequoia/Tahoe
Publication date: 2026-02-11
Last updated on: 2026-02-13
Assigner: Apple Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apple | macos | From 15.0 (inc) to 15.7.4 (exc) |
| apple | macos | From 26.0 (inc) to 26.3 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is related to a logging issue in certain versions of macOS (Sequoia 15.7.4 and Tahoe 26.3). The problem involved insufficient data redaction in logs, which could allow an application to access sensitive user data that should have been protected.
How can this vulnerability impact me? :
If exploited, this vulnerability could allow an application to access sensitive user data through improperly redacted logs. This could lead to unauthorized disclosure of personal or confidential information.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
I don't know
How can this vulnerability be detected on my network or system? Can you suggest some commands?
I don't know
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, update your system to macOS Sequoia 15.7.4 or macOS Tahoe 26.3 where the issue has been fixed.