Impact
An out‑of‑bounds read bug in multiple Apple operating systems allows a malicious application to read kernel memory. This vulnerability is a CWE‑125 flaw that can expose sensitive kernel data, potentially leaking information that could be used in further attacks.
Affected Systems
Affected vendors include Apple with iOS, iPadOS, macOS, tvOS, visionOS and watchOS. Fixes are shipped in iOS 26 and iPadOS 26, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26, tvOS 26, visionOS 26 and watchOS 26.
Risk and Exploitability
The CVSS score of 7.8 reflects a high impact, while the EPSS score indicates a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to install a malicious app on the device, so the attack vector is local to the user’s device. Even with a low EPSS, the potential for confidential data exposure warrants prompt mitigation.
OpenCVE Enrichment