CVE-2025-24218 Overview
CVE-2025-24218 is an information disclosure vulnerability in Apple macOS that allowed an application to access information about a user's contacts through insufficiently redacted log entries. Apple addressed the issue by improving private data redaction for log entries in macOS Sequoia 15.4. The flaw is categorized under [CWE-284] Improper Access Control and requires local access with user interaction to exploit.
Critical Impact
A local application on an affected macOS system could read contact data belonging to the current user by parsing system log entries that failed to redact private information.
Affected Products
- Apple macOS versions prior to Sequoia 15.4
Discovery Timeline
- 2025-03-31 - CVE-2025-24218 published to the National Vulnerability Database (NVD)
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-24218
Vulnerability Analysis
The vulnerability resides in macOS logging subsystems that recorded contact-related information without applying the private data redaction expected for sensitive personal data. Apple's unified logging framework normally marks fields containing personally identifiable information as private so they appear redacted in log output. In this case, contact data reached log entries in plaintext form, allowing any process with access to those logs to harvest user contact records.
The issue is a confidentiality-only bug. It does not permit modification of data, code execution, or service disruption. Exploitation requires an application already running on the target Mac and some form of user interaction, consistent with the CVSS local attack vector.
Root Cause
The root cause is missing or incorrect use of the %{private} format specifier and related redaction primitives when contact information was passed to the logging subsystem. Without proper redaction annotations, os_log stored raw contact fields rather than the redacted <private> placeholder. Apple's fix in macOS Sequoia 15.4 adds the missing redaction to the affected log call sites.
Attack Vector
A local, non-privileged application can query the unified logging store using standard APIs such as log show or the OSLog framework. If the application ships with an appropriate purpose string and the user grants log access, or if the process runs under a user context that already has read access to the relevant log entries, it can extract contact names, phone numbers, or email addresses without the Contacts permission normally required by the TCC (Transparency, Consent, and Control) subsystem. This effectively bypasses the intended Contacts access control by reading the same data from a side channel.
No verified proof-of-concept code is publicly available. See the Apple Support Document and the Full Disclosure Mailing List Post for additional technical context.
Detection Methods for CVE-2025-24218
Indicators of Compromise
- Unexpected processes invoking log show, log stream, or the OSLog API with predicates targeting Contacts, AddressBook, or CNContact subsystems.
- Applications requesting the com.apple.developer.log-access entitlement or prompting the user for log access without a clear operational need.
- macOS endpoints running builds earlier than Sequoia 15.4 that host third-party apps handling personal data.
Detection Strategies
- Inventory macOS endpoints and flag any host on a version below macOS Sequoia 15.4 as exposed to CVE-2025-24218.
- Monitor for command-line invocations of log, sysdiagnose, or archive collection utilities executed by non-administrative user sessions.
- Review installed applications for entitlements that grant broad access to the unified logging store and correlate with the vendor's stated purpose.
Monitoring Recommendations
- Forward macOS endpoint telemetry, including process execution and entitlement usage, to a central analytics platform for retrospective hunting.
- Alert on user-space processes that read or export .logarchive bundles outside of IT-driven diagnostic workflows.
- Track TCC prompt patterns to identify apps attempting to sidestep the Contacts permission by pivoting to log-based data collection.
How to Mitigate CVE-2025-24218
Immediate Actions Required
- Update all affected Macs to macOS Sequoia 15.4 or later, which contains the improved redaction logic from Apple.
- Audit third-party applications that request log access entitlements and remove those without a documented business need.
- Restrict local user accounts on shared or multi-user Macs to limit which processes can query the unified logging store.
Patch Information
Apple resolved CVE-2025-24218 in macOS Sequoia 15.4 by improving private data redaction for log entries. Refer to the Apple Support Document for the full list of security content and update instructions.
Workarounds
- On systems that cannot be patched immediately, remove or disable applications that are not from trusted publishers to reduce local attack surface.
- Clear existing log archives that may contain unredacted contact data using log erase after backing up any records needed for troubleshooting.
- Enforce Mobile Device Management (MDM) profiles that restrict installation of unsigned or unnotarized applications on managed endpoints.
# Verify macOS build and remove stale log data after patching
sw_vers -productVersion
sudo log erase --all
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
