Description
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to disclose kernel memory.
Published: 2026-07-27
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An application that runs on Apple devices can read kernel memory due to improper memory handling. This vulnerability allows the attacker to expose protected data that should not be reachable outside the kernel, thereby compromising confidentiality. The weakness is a classic memory protection flaw and falls under information exposure.

Affected Systems

Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are affected. The issue is mitigated in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6.

Risk and Exploitability

The CVSS score of 5.5 indicates a moderate impact. The EPSS score of < 1% shows that the likelihood of exploitation is very low, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through a third‑party application that exploits the memory handling error; this inference is necessary as the exact method is not described.

Generated by OpenCVE AI on August 4, 2026 at 23:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest OS updates for iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6
  • Restart the device after installing the update to ensure changes take effect
  • Enable automatic updates or check with Apple for the latest security patches

Generated by OpenCVE AI on August 4, 2026 at 23:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Kernel Memory Disclosure via Improper Memory Handling in Apple Operating Systems

Mon, 03 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Kernel Memory Disclosure via Improper Memory Handling
Weaknesses CWE-122

Thu, 30 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Kernel Memory Disclosure via Improper Memory Handling
Weaknesses CWE-122

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to disclose kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T14:29:18.017Z

Reserved: 2026-07-20T18:09:24.049Z

Link: CVE-2026-64709

cve-icon Vulnrichment

Updated: 2026-07-28T14:29:09.325Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:10.267

Modified: 2026-07-28T19:56:28.267

Link: CVE-2026-64709

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T00:00:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor