Description
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be able to disclose kernel memory.
Published: 2025-05-12
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory disclosure
Action: Patch
AI Analysis

Impact

An application can read kernel memory due to an issue with how the operating system manages memory. The flaw allows an attacker to retrieve sensitive data stored in kernel space, which can lead to further compromise if the attacker obtains privileged information or extends the attack surface. The weakness matches CWE-200, which is about information exposure.

Affected Systems

All Apple macOS installations are potentially vulnerable; the vulnerability is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.6 and macOS Ventura 13.7.6, so any earlier releases of these macOS versions remain affected.

Risk and Exploitability

The CVSS score of 5.5 indicates a moderate severity, and the EPSS score of less than 1% suggests that exploitation is currently unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local, meaning the attacker must run code on the target device to trigger the memory disclosure. Because no public exploitation exists, the immediate risk is limited, but the flaw still permits the compromise of confidential kernel data.

Generated by OpenCVE AI on April 28, 2026 at 11:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the system to macOS Sequoia 15.3 or later, macOS Sonoma 14.7.6 or later, or macOS Ventura 13.7.6 or later
  • Restrict local privileges by ensuring users run only necessary applications and avoid running privileged code from untrusted sources
  • Enable and review system logging – monitor for any unexpected kernel memory access patterns and investigate anomalies promptly

Generated by OpenCVE AI on April 28, 2026 at 11:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-14862 The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3, macOS Ventura 13.7.6, macOS Sonoma 14.7.6. An app may be able to disclose kernel memory.
History

Tue, 28 Apr 2026 11:45:00 +0000

Type Values Removed Values Added
Title Kernel Memory Disclosure Vulnerability via Improper Memory Handling in macOS

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3, macOS Ventura 13.7.6, macOS Sonoma 14.7.6. An app may be able to disclose kernel memory. The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be able to disclose kernel memory.

Mon, 03 Nov 2025 20:30:00 +0000


Tue, 27 May 2025 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos

Wed, 14 May 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 12 May 2025 21:45:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3, macOS Ventura 13.7.6, macOS Sonoma 14.7.6. An app may be able to disclose kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:17:10.616Z

Reserved: 2025-01-17T00:00:44.985Z

Link: CVE-2025-24155

cve-icon Vulnrichment

Updated: 2025-05-14T13:29:58.015Z

cve-icon NVD

Status : Modified

Published: 2025-05-12T22:15:19.913

Modified: 2026-04-02T19:19:08.817

Link: CVE-2025-24155

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T11:30:29Z

Weaknesses