Impact
An application may be able to read privileged kernel memory due to an improper memory handling issue that was addressed in recent Apple operating system releases. This flaw could allow an attacker to access confidential kernel data and, by extension, gain further exploitation potential. The weakness is an information‑exposure problem under CWE‑497, which involves leaking sensitive data from privileged memory.
Affected Systems
Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are affected. The issue exists in iOS 18.7.9 and iOS 26.5, iPadOS 18.7.9 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, and watchOS 26.5. Upgrading to the documented fixed releases removes the vulnerability.
Risk and Exploitability
The EPSS score is < 1% and the CVSS score is 7.5, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could deliver malicious code within an app and exploit the memory handling issue to read kernel data; the likely attack vector is local code execution on a device running one of the affected OS versions. The absence of published exploitation manifests suggests the vector is currently limited, yet the potential damage warrants timely remediation.
OpenCVE Enrichment