Apple StoreKit Privacy Vulnerability in Multiple macOS and iPadOS Versions

Vulnerability

A privacy vulnerability has been identified in the StoreKit framework, available on iPadOS 17.7.7, macOS Ventura 13.7.6, macOS Sequoia 15.5, and macOS Sonoma 14.7.6. This issue allows an app to access sensitive user data without proper authorization. The vulnerability arises from inadequate private data redaction in log entries, which could enable unauthorized data access.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive user data.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
4.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.