Apple macOS WindowServer Vulnerability Allowing Sensitive Data Access on Locked Devices

Vulnerability

A vulnerability in the WindowServer component of Apple macOS releases Sequoia 15.6, Sonoma 14.7.7, and Ventura 13.7.7 allows an attacker with physical access to a locked device to view sensitive user information. This issue stems from inadequate redaction of private data, which could be exploited to access protected information.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive user data on a locked device.

Added: Jul 30, 2025, 12:39 AM
Updated: Jul 30, 2025, 12:39 AM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
3.3
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.