Impact
An input sanitization flaw allows a compromised application to access and expose sensitive kernel state, potentially revealing confidential system data. The vulnerability manifests only when malicious or poorly designed input is processed by the operating system, enabling an attacker to read limited kernel memory without broader system control.
Affected Systems
Apple iOS, iPadOS, and macOS environments are affected. The flaw is present in code versions prior to iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2, and is fixed in those releases.
Risk and Exploitability
No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog, so its exploitation likelihood is uncertain, yet the potential for kernel data leakage is high. The likely attack vector involves a malicious or suspicious application sending specially crafted input to trigger the sanitization flaw. Successful exploitation would allow an attacker to read restricted kernel memory, compromising confidentiality. The severity of the impact depends on the sensitivity of the leaked kernel data and the attacker’s access level, but it is sufficient to justify a fast remediation.
OpenCVE Enrichment