Description
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to disclose kernel memory.
Published: 2026-07-27
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A memory corruption flaw in Apple operating systems allows a malicious or compromised application to read kernel memory, potentially exposing privileged data such as device credentials or cryptographic keys. The vulnerability originates from an uncontrolled buffer read, classified as CWE-119, and can be leveraged to extract sensitive information without requiring elevated privileges at the time of exploitation.

Affected Systems

All Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS releases prior to the patched versions are affected. The patched releases are iOS 18.7.10, iPadOS 18.7.10, iOS 26.5, iPadOS 26.5, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, and watchOS 26.5. Devices running earlier releases of these operating systems remain vulnerable.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, while an EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to execute code within the context of a user‑space application or via a malicious third‑party app; it is unlikely to be remotely exploitable without local access or application compromise.

Generated by OpenCVE AI on August 26, 2026 at 05:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS devices to the patched releases listed above.
  • If an upgrade is not immediately possible, restrict installation of apps from unofficial or untrusted sources and enforce strict app sandboxing to limit local application privileges.
  • Ensure that System Integrity Protection and kernel memory protection features are enabled so that user‑space processes cannot alter kernel memory without proper authorization.

Generated by OpenCVE AI on August 26, 2026 at 05:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Kernel Memory Disclosure via Memory Corruption in Apple Operating Systems

Tue, 25 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to disclose kernel memory. A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to disclose kernel memory.
References

Tue, 18 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Kernel Memory Disclosure via Out-of-Bounds Read in macOS

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to disclose kernel memory. A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to disclose kernel memory.
References

Tue, 04 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Title Kernel Memory Disclosure via Out-of-Bounds Read in macOS

Mon, 03 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Kernel Memory Disclosure in macOS via Memory Corruption
Weaknesses CWE-250

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Kernel Memory Disclosure in macOS via Memory Corruption
Weaknesses CWE-119
CWE-250
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to disclose kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-25T19:24:52.869Z

Reserved: 2026-04-07T19:58:20.174Z

Link: CVE-2026-39877

cve-icon Vulnrichment

Updated: 2026-07-28T14:20:57.181Z

cve-icon NVD

Status : Modified

Published: 2026-07-27T21:16:51.640

Modified: 2026-08-25T20:16:55.103

Link: CVE-2026-39877

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T05:15:04Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer