Description
The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to disclose kernel memory.
Published: 2025-03-31
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Memory Disclosure
Action: Patch
AI Analysis

Impact

The vulnerability appears to be a buffer overread caused by insufficient bounds checking in the macOS kernel, resulting in the potential disclosure of kernel memory. This inference is drawn from the description that the issue was addressed with improved bounds checks and that an app may be able to disclose kernel memory. The flaw primarily compromises confidentiality by exposing privileged kernel data, which could, in turn, be leveraged by an attacker for further attacks.

Affected Systems

Apple macOS versions prior to macOS Sequoia 15.4, macOS Sonoma 14.7.5, and macOS Ventura 13.7.5 are affected. Any system running an unpatched kernel version of these releases can be targeted by a local application that triggers the overread.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity, while the EPSS score of less than 1% suggests a low current probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, implying no known widespread active exploitation. The attack vector appears to be local, inferred because the description cites an app that can disclose kernel memory; remote exploitation is not indicated in the available data.

Generated by OpenCVE AI on April 28, 2026 at 11:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest macOS updates that include the kernel bounds check fix (macOS Sequoia 15.4, Sonoma 14.7.5, Ventura 13.7.5).
  • If an update cannot be deployed immediately, restrict the execution of unsigned or untrusted applications using Gatekeeper and maintain restricted user accounts to limit local exploitation.
  • Enable System Integrity Protection and maintain regular backups to reduce impact and facilitate recovery if any memory disclosure occurs.

Generated by OpenCVE AI on April 28, 2026 at 11:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8950 The issue was addressed with improved bounds checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to disclose kernel memory.
History

Tue, 28 Apr 2026 12:15:00 +0000

Type Values Removed Values Added
Title Kernel Memory Disclosure via Improper Bounds Check

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved bounds checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to disclose kernel memory. The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to disclose kernel memory.

Mon, 03 Nov 2025 22:30:00 +0000


Mon, 07 Apr 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos

Tue, 01 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 31 Mar 2025 22:45:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved bounds checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to disclose kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:10:28.193Z

Reserved: 2025-01-17T00:00:45.013Z

Link: CVE-2025-24256

cve-icon Vulnrichment

Updated: 2025-11-03T21:11:17.506Z

cve-icon NVD

Status : Modified

Published: 2025-03-31T23:15:22.570

Modified: 2026-04-02T19:19:28.560

Link: CVE-2025-24256

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T12:00:13Z

Weaknesses