Impact
An issue with memory handling in Apple operating systems allows a malicious NFS server to read kernel memory. The vulnerability exists in the NFS implementation and can lead to disclosure of internal data, potentially compromising the confidentiality of kernel information.
Affected Systems
Affected Apple operating systems include iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27 and macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of < 1 % suggests a low likelihood of exploitation. The vulnerability is not listed in CISA KEV, indicating it has not yet been observed in widespread exploitation. The likely attack vector is remote over the network, requiring the ability to initiate an NFS session with a device running the affected software (inferred). Because no current exploitation evidence exists, the risk remains theoretical until the vulnerability is actively leveraged.
OpenCVE Enrichment