First published: Mon Oct 28 2024(Updated: )
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.1. A user may be able to view sensitive user information.
Credit: product-security@apple.com Junsung Lee Trend Micro Zero Day InitiativeJex Amro Zhongquan Li @Guluisacat Mickey Jin @patch1t Wang Yu CyberservalYe Zhang @VAR10CK Baidu Securityan anonymous researcher Mateusz Krzywicki @krzywix Garrett Moon Excited Pixel LLCArsenii Kostromin (0x3c3e) Ben Roeder Toomas Römer Jaime Bertran Kirin @Pwnrin Noah Gregory (wts.dev) 7feilee Un3xploitable CW Research IncBohdan Stasiuk @Bohdan_Stasiuk CW Research IncPedro Tôrres @t0rr3sp3dr0 Mickey Jin @patch1t KandjiCsaba Fitzl @theevilbit Kandjian anonymous researcher Dawn Security Lab of JDYinyi Wu @_3ndy1 Dawn Security Lab of JDNarendra Bhati Cyber Security at Suma Soft PvtManager Cyber Security at Suma Soft PvtPune (India) Lucas Di Tomase Ryan Dowd @_rdowd Gergely Kalman @gergely_kalman Csaba Fitzl @theevilbit Michael DePlante @izobashi Trend Micro Zero Day InitiativeHalle Winkler Politepix (theoffcuts.org) Bing Shi Alibaba GroupWenchao Li Alibaba GroupXiaolong Bai Alibaba Group Indiana University BloomingtonLuyi Xing Indiana University BloomingtonHossein Lotfi @hosselot Trend Micro Zero Day Initiativedw0r! Trend Micro Zero Day InitiativeRodolphe Brunetti @eisw0lf Cristian Dinca (icmd.tech) Wojciech Regula SecuRingQ1IQ @q1iqF P1umer @p1umer Bohdan Stasiuk @Bohdan_Stasiuk Ivan Fratric Google Project ZeroK宝 @Pwnrin pattern-f @pattern_F_ Loadshine LabHikerell Loadshine LabAlexandre Bedard Ronny Stiftel CVE-2024-39573 CVE-2024-38477 CVE-2024-38476
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | =15.0 | |
macOS | <15.1 | 15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2024-44293 is classified as a privacy issue that can lead to exposure of sensitive user information.
To address CVE-2024-44293, users should upgrade to macOS Sequoia version 15.1 or later.
CVE-2024-44293 affects sensitive user information that may be inadequately redacted in log entries.
Users of macOS Sequoia version 15.0 are affected by CVE-2024-44293.
Yes, CVE-2024-44293 specifically affects the Apple macOS operating system.