CVE-2025-51497

An issue was discovered in AdGuard plugin before 1.11.22 for Safari on MacOS. AdGaurd verbosely logged each url that Safari accessed when the plugin was active. These logs went into the MacOS general logs for any unsandboxed process to read. This may be disabled in version 1.11.22.
Configurations

Configuration 1 (hide)

cpe:2.3:a:adguard:adguard_for_safari:*:*:*:*:*:macos:*:*

History

09 Oct 2025, 19:13

Type Values Removed Values Added
CPE cpe:2.3:a:adguard:adguard_for_safari:*:*:*:*:*:macos:*:*
References () https://adguard.com/en/adguard-safari/overview.html - () https://adguard.com/en/adguard-safari/overview.html - Product
References () https://github.com/AdguardTeam/AdGuardForSafari - () https://github.com/AdguardTeam/AdGuardForSafari - Product
References () https://www.mcrich23.com/post/adguard-messed-up-their-logging - () https://www.mcrich23.com/post/adguard-messed-up-their-logging - Third Party Advisory
First Time Adguard
Adguard adguard For Safari

24 Jul 2025, 21:15

Type Values Removed Values Added
Summary
  • (es) Se detectó un problema en el complemento AdGuard para Safari en macOS, antes de la versión 1.11.22. AdGuard registraba detalladamente cada URL a la que Safari accedía cuando el complemento estaba activo. Estos registros se guardaban en los registros generales de macOS para que cualquier proceso no protegido los pudiera leer. Es posible que esto esté deshabilitado en la versión 1.11.22.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE CWE-532

17 Jul 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-17 18:15

Updated : 2025-10-09 19:13


NVD link : CVE-2025-51497

Mitre link : CVE-2025-51497

CVE.ORG link : CVE-2025-51497


JSON object : View

Products Affected

adguard

  • adguard_for_safari
CWE
CWE-532

Insertion of Sensitive Information into Log File