Impact
This vulnerability, which existed before the improvement, arises from insufficient input sanitization in the operating system, allowing a malicious or poorly designed application to read sensitive kernel state. An app may be able to leak sensitive kernel state. The flaw is triggered by crafted input that the system passes to kernel routines without proper validation, enabling data leakage. The exposed data can contain confidential system information but the flaw does not grant full device control.
Affected Systems
Apple iOS, iPadOS, and macOS systems are affected. The issue exists in code versions prior to iOS 26.5.2, iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.5.2, which have been patched in those releases.
Risk and Exploitability
The EPSS score of less than 1% indicates a low probability of exploitation, and the CVSS score of 5.5 reflects a moderate impact. The vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed exploitation in the wild. The likely attack vector is an attacker installing a malicious or compromised application that supplies specially crafted input to trigger the sanitization flaw, resulting in the reading of kernel memory and exposure of confidential data. Even though exploitation is considered unlikely, the confidentiality risk to the operating system’s kernel state warrants timely mitigation.
OpenCVE Enrichment