Impact
The flaw arises from insufficient redaction of sensitive information within the operating systems, allowing a locally running application on macOS, iOS, or iPadOS to read privileged kernel state that should be protected. This can lead to leakage of confidential data, potentially exposing user information and system configuration, and represents a direct information‑exposure weakness affecting the confidentiality of privileged data.
Affected Systems
Apple’s macOS, iOS, and iPadOS operating systems are affected. Versions before macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, iOS 18.7.10, and iPadOS 18.7.10 contain the flaw. Systems running those earlier releases remain vulnerable, and any local application that can execute with sufficient privileges may exploit the issue.
Risk and Exploitability
The exposure of kernel state constitutes a moderate‑level information‑exposure vulnerability; leakage of privileged data might allow an attacker to gain sensitive knowledge that could be leveraged in subsequent attacks. The EPSS score remains under 1%, indicating a very low likelihood of exploitation at present. The flaw can be triggered by a local application that runs with sufficient user or privileged privileges on macOS, iOS, or iPadOS, and then reads the unredacted kernel memory. The combination of a simple local execution path and the ability to retrieve confidential information means that, while exploitation is currently improbable, the risk remains if the attacker can gain local execution.
OpenCVE Enrichment