Impact
An input sanitization flaw in the operating system permits a malicious or poorly designed application to access and expose sensitive kernel memory. The vulnerability is a classic boundary‑breach that enables reading of restricted kernel state, which can contain confidential system data. The flaw leverages improper sanitization of data before it is passed to low‑level kernel routines, allowing leakage of kernel‑level information without granting full control of the device.
Affected Systems
Apple iOS, iPadOS, and macOS systems are affected. The issue is present in all code versions prior to iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2, and was patched in those releases.
Risk and Exploitability
The EPSS score of less than 1% indicates a low probability of exploitation, and the CVSS score of 5.5 reflects a moderate impact. The vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed exploitation in the wild. The likely attack vector is an attacker installing a malicious or compromised application that supplies specially crafted input to trigger the sanitization flaw, resulting in the reading of kernel memory and exposure of confidential data. Even though exploitation is considered unlikely, the confidentiality risk to the operating system’s kernel state warrants timely mitigation.
OpenCVE Enrichment