
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-43508 is a logging issue in the Phone component of Apple macOS Tahoe that allows a locally-installed app to access sensitive user data through insufficiently redacted log entries. The vulnerability was discovered by Wojciech Regula of SecuRing and disclosed by Apple on November 3, 2025, with the CVE entry added to the advisory on January 16, 2026. It affects macOS Tahoe 26.0 and is fixed in macOS Tahoe 26.1. The CVSS v3.1 base score is 5.5 (Medium) (Apple Advisory, Feedly).
The root cause is classified as CWE-532 (Insertion of Sensitive Information into Log File), where the Phone component on macOS Tahoe failed to adequately redact sensitive user data before writing it to system logs. Apple addressed the issue with improved data redaction in log output. Exploitation requires local access and low privileges — an attacker-controlled app running on the system could read system or application logs to extract sensitive user information without requiring user interaction or elevated permissions (Apple Advisory, Feedly).
Successful exploitation allows a locally-installed app to access sensitive user data associated with the Phone component, resulting in a high confidentiality impact with no effect on integrity or availability. The scope is limited to the local system, but exposed data could include call-related information or other user-sensitive details logged by the Phone subsystem. There is no evidence of lateral movement potential or remote exploitation capability (Apple Advisory, Feedly).
log show or the OSLog API) to retrieve log entries generated by the Phone component.Apple has released macOS Tahoe 26.1, which addresses this vulnerability through improved data redaction in log output. Users running macOS Tahoe 26.0 should update to macOS Tahoe 26.1 as soon as possible. No configuration-based workaround is available; updating to the patched release is the only recommended remediation (Apple Advisory).
The vulnerability was credited to Wojciech Regula of SecuRing (wojciechregula.blog), a well-known macOS security researcher. No significant public commentary, media coverage, or social media discussion specific to this CVE has been identified beyond standard vulnerability tracking and aggregation sites (Apple Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."