Impact
An improper memory handling flaw allows a malicious application to read portions of kernel memory, potentially revealing low‑level system state, cryptographic keys, or other sensitive data. The vulnerability is classified as a confidentiality breach (CWE-200) and, if exploited, could enable privilege escalation or further exploitation of the operating system.
Affected Systems
Apple macOS is the impacted vendor. The flaw is fixed in macOS Sequoia 15.6 and macOS Sonoma 14.7.7; earlier releases of these macOS versions remain vulnerable until patched.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, while the EPSS score of less than 1% suggests a small likelihood of immediate exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to run a malicious application locally on the target machine; thus the attack vector is likely local. Given the high impact on confidentiality, the flaw warrants urgent attention.
OpenCVE Enrichment
EUVD