Impact
The vulnerability appears to be a buffer overread caused by insufficient bounds checking in the macOS kernel, resulting in the potential disclosure of kernel memory. This inference is drawn from the description that the issue was addressed with improved bounds checks and that an app may be able to disclose kernel memory. The flaw primarily compromises confidentiality by exposing privileged kernel data, which could, in turn, be leveraged by an attacker for further attacks.
Affected Systems
Apple macOS versions prior to macOS Sequoia 15.4, macOS Sonoma 14.7.5, and macOS Ventura 13.7.5 are affected. Any system running an unpatched kernel version of these releases can be targeted by a local application that triggers the overread.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, while the EPSS score of less than 1% suggests a low current probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, implying no known widespread active exploitation. The attack vector appears to be local, inferred because the description cites an app that can disclose kernel memory; remote exploitation is not indicated in the available data.
OpenCVE Enrichment
EUVD