Impact
The vulnerability remains tied to insufficient input sanitization in the operating system, which an application can exploit to read sensitive kernel state. It is triggered when crafted input is passed to kernel routines without proper validation, permitting data leakage. The exposed data can include confidential system information, although the flaw does not grant full device control. The issue is addressed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.5.2.
Affected Systems
Apple iOS, iPadOS, and macOS systems are affected. The issue exists in code versions prior to iOS 26.5.2, iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.5.2, which have been patched in those releases.
Risk and Exploitability
The EPSS score of less than 1% indicates a low probability of exploitation, and the CVSS score of 5.5 reflects a moderate impact. The vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed exploitation in the wild. The likely attack vector is an attacker installing a malicious or compromised application that supplies specially crafted input to trigger the sanitization flaw, resulting in the reading of kernel memory and exposure of confidential data. Even though exploitation is considered unlikely, the confidentiality risk to the operating system’s kernel state warrants timely mitigation.
OpenCVE Enrichment