
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-43538 is a logging information disclosure vulnerability in Apple's Screen Time component that allows a local app to access sensitive user data due to insufficient data redaction in log entries. It was discovered by Iván Savransky and disclosed on December 12, 2025, as part of Apple's coordinated security update. The vulnerability affects macOS Sonoma prior to 14.8.3, iOS and iPadOS prior to 18.7.3 and 26.2, macOS Tahoe prior to 26.2, visionOS prior to 26.2, and watchOS prior to 26.2. It carries a CVSS v3.1 base score of 5.5 (Medium) per NIST NVD, while CISA-ADP assessed it at 3.3 (Low) (Apple Advisory macOS, Apple Advisory iOS 26.2, Apple Advisory iOS 18.7.3).
The root cause is classified under CWE-532 (Insertion of Sensitive Information into Log File) and CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The Screen Time subsystem failed to adequately redact sensitive user data before writing it to system log files, allowing a locally installed app with low privileges to read those log entries and access data it should not be permitted to view. The attack vector is local, requires low privileges, no user interaction, and no elevated complexity — meaning any app running on the device could potentially query system logs to extract the exposed data. Apple addressed the issue by implementing improved data redaction in the logging pipeline (Apple Advisory macOS, Apple Advisory iOS 26.2).
Successful exploitation allows a malicious or compromised app to read sensitive user data that the Screen Time component inadvertently wrote to system logs without proper redaction. The primary impact is a high confidentiality loss — potentially exposing personal usage data, browsing history, or other Screen Time-tracked information — with no integrity or availability impact. Because the attack is local and scoped to the affected device, lateral movement risk is limited, but the exposed data could be leveraged for privacy violations or targeted social engineering (Apple Advisory macOS).
Apple has released patches addressing this vulnerability across all affected platforms. Users should update to macOS Sonoma 14.8.3, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, or watchOS 26.2. No configuration-based workaround is available; updating to a patched version is the only recommended remediation. Organizations should prioritize patching devices where Screen Time is enabled and sensitive user data is present (Apple Advisory macOS, Apple Advisory iOS 26.2, Apple Advisory iOS 18.7.3, Apple Advisory visionOS).
The vulnerability was reported by security researcher Iván Savransky and credited in Apple's official advisories. It was part of a broader December 2025 Apple security update that also addressed more severe WebKit zero-days (CVE-2025-43529, CVE-2025-14174) that received significantly more media attention. Coverage of CVE-2025-43538 specifically was limited, with most reporting focused on the actively exploited WebKit flaws in the same release batch (Apple Advisory macOS, Apple Advisory iOS 26.2).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."