Description
A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to disclose kernel memory.
Published: 2026-07-27
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An Apple macOS memory initialization flaw can allow a local application to read kernel memory that should be protected. This weakness may expose sensitive information contained in kernel memory. The vulnerability is an example of improper handling of memory, allowing confidential data to be disclosed.

Affected Systems

The issue affects macOS running on Apple devices before the release of macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6. The specified updates contain the fix, so earlier builds of those macOS versions are susceptible.

Risk and Exploitability

The EPSS score is < 1% and the CVSS score is 5.5, indicating moderate risk. The vulnerability is not listed in the CISA KEV catalog, suggesting there are no known public exploits. The likely attack vector is inferred to be local, as any local application with execution privileges could potentially exploit the flaw.

Generated by OpenCVE AI on August 3, 2026 at 16:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest macOS updates that include the fix for macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6.
  • Avoid running untrusted applications that may exploit memory handling; restrict third‑party software usage.
  • If immediate update is not possible, limit the use of applications with elevated privileges and monitor for suspicious memory‑access activity.

Generated by OpenCVE AI on August 3, 2026 at 16:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Kernel Memory Disclosure in macOS via Improper Memory Initialization

Sun, 02 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
Title Kernel Memory Disclosure via Improper Memory Initialization
Weaknesses CWE-200
CWE-221

Thu, 30 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Kernel Memory Disclosure via Improper Memory Initialization
Weaknesses CWE-200
CWE-221

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-457
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to disclose kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T14:26:22.858Z

Reserved: 2026-07-20T18:09:01.158Z

Link: CVE-2026-64699

cve-icon Vulnrichment

Updated: 2026-07-28T14:26:13.491Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:09.587

Modified: 2026-07-28T20:00:14.287

Link: CVE-2026-64699

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T16:15:03Z

Weaknesses
  • CWE-457

    Use of Uninitialized Variable