Impact
A race condition was discovered in the kernel memory handling of macOS. The flaw permits a local user to read portions of kernel memory that should remain protected, potentially exposing sensitive data. Based on the description, it is inferred that this local memory disclosure could be used as a stepping stone for privilege escalation, since kernel memory holds privileged information.
Affected Systems
Apple’s macOS versions before macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 are affected. Any release at or newer than those contains the fixing locking changes and removes the race condition.
Risk and Exploitability
The EPSS score is < 1 % and the vulnerability is not listed in CISA KEV. The CVSS score is 4.7. Based on the description, it is inferred that because the condition is local, exploitation requires physical or authorized user access. If achieved, the attacker can read kernel memory and potentially elevate privileges. The low EPSS indicates low public exploitation likelihood, but the impact remains high if locally exploited.
OpenCVE Enrichment