Impact
A memory corruption flaw in Apple operating systems allows a malicious or compromised application to read kernel memory, potentially exposing privileged data such as device credentials or cryptographic keys. The vulnerability originates from an uncontrolled buffer read, classified as CWE-119, and can be leveraged to extract sensitive information without requiring elevated privileges at the time of exploitation.
Affected Systems
All Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS releases prior to the patched versions are affected. The patched releases are iOS 18.7.10, iPadOS 18.7.10, iOS 26.5, iPadOS 26.5, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, and watchOS 26.5. Devices running earlier releases of these operating systems remain vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while an EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to execute code within the context of a user‑space application or via a malicious third‑party app; it is unlikely to be remotely exploitable without local access or application compromise.
OpenCVE Enrichment