Executive brief
A security issue in the macOS App Store component could allow a malicious application installed on a computer to access sensitive user information. This occurs because the system was recording private data into system logs without proper masking. Users should update to macOS Tahoe 26.1 to ensure their private information is correctly redacted from these logs.
Technical details
A logging vulnerability existed in the App Store component of macOS Tahoe where sensitive user data was written to system logs in plaintext. An application with the ability to read system logs could potentially harvest this sensitive information. The root cause was a failure to properly redact private data before it was committed to the logging subsystem. Apple addressed this issue in macOS Tahoe 26.1 by implementing improved data redaction mechanisms. Exploitation requires a malicious app to be present on the local system but does not necessarily require elevated privileges depending on the log's visibility.
Affected products
- Apple macOS Tahoe Before 26.1
Timeline
- 2025-11-03: patched: Issue fixed in macOS Tahoe 26.1
- 2026-06-11: disclosed: CVE record published