Intel

AIKIDO-2025-10752

Sentry is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

Exposure of Sensitive Information to an Unauthorized Actor Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 28, 2025

48

Medium Risk

This Affects:

SwiftSentry
8.31.1 - 8.56.2
Fixed in 8.57.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package disable Session Replay by default on iOS 26.0+ when built with Xcode 26.0 or later to prevent potential PII (Personally identifiable information) leaks. This mitigation addresses masking issues introduced by Apple’s new Liquid Glass rendering, which can expose sensitive user data during session recording. Developers can temporarily re-enable Session Replay using options.experimental.enableSessionReplayInUnreliableEnvironment = true, but doing so carries privacy risks.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

Sentry is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 8.31.1 - 8.56.2.

How to fix this

Upgrade the Sentry library to the patch version.