Sensitive information logged in plaintext in Swift

Sensitive information logged in plaintext in Swift

Description

Logging passwords, tokens, session identifiers, API keys, or other sensitive information through print, NSLog, os_log, or Logger can expose those values to anyone with access to device logs, crash collectors, or operational logs.

Potential impact

  • Theft of authentication tokens or sessions.
  • Exposure of personal information and internal API keys.
  • Spread of sensitive information through log collection systems.

Remediation

  1. Do not log sensitive values.
  2. When necessary, log only a fixed masking string or a separate tracking ID.
  3. Use a shared redaction helper or logging filter to remove sensitive fields centrally.

Examples

Before

swift
func logToken(token: String) {
    NSLog("token %@", token)
}

After

swift
func logToken() {
    NSLog("token refreshed")
}

Explanation:

  • Before: Writing the token directly to a log exposes an authentication value to anyone who can read that log.
  • After: The log records only the event, without the sensitive value itself.

References