Impact
An application on macOS, iOS, or iPadOS may be able to read and disclose kernel memory through an information‑leak vulnerability that was mitigated with additional validation. When triggered, the flaw allows an app to leak sensitive kernel data, potentially exposing confidential information stored in system memory. The issue is fixed in iOS 18.7.10, iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6, but earlier releases are vulnerable. The CVSS score of 5.5 reflects a moderate severity.
Affected Systems
Apple macOS, iOS, and iPadOS platforms are affected. The vulnerability is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, iOS 18.7.10, and iPadOS 18.7.10. All earlier releases of these operating systems are vulnerable.
Risk and Exploitability
The EPSS score of <1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 5.5 reflects moderate threat potential. The likely attack vector is an application running with sufficient privileges attempting to read kernel space, though exact conditions are not detailed.
OpenCVE Enrichment