Description
An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to disclose kernel memory.
Published: 2026-07-27
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An application on macOS, iOS, or iPadOS may be able to read and disclose kernel memory through an information‑leak vulnerability that was mitigated with additional validation. When triggered, the flaw allows an app to leak sensitive kernel data, potentially exposing confidential information stored in system memory. The issue is fixed in iOS 18.7.10, iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6, but earlier releases are vulnerable. The CVSS score of 5.5 reflects a moderate severity.

Affected Systems

Apple macOS, iOS, and iPadOS platforms are affected. The vulnerability is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, iOS 18.7.10, and iPadOS 18.7.10. All earlier releases of these operating systems are vulnerable.

Risk and Exploitability

The EPSS score of <1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 5.5 reflects moderate threat potential. The likely attack vector is an application running with sufficient privileges attempting to read kernel space, though exact conditions are not detailed.

Generated by OpenCVE AI on August 18, 2026 at 00:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade your system to macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, or macOS Tahoe 26.6, whichever applies to your machine.
  • If an immediate OS update is not feasible, restrict the installation and execution of applications to those signed and trusted by Apple, limiting the attacker’s ability to inject code into the kernel context.
  • Monitor your system logs and kernel activity for unusual memory access patterns that may indicate an attempt to exploit kernel memory.

Generated by OpenCVE AI on August 18, 2026 at 00:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Kernel Memory Disclosure via Information Leaking Vulnerability in macOS

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description An information leakage was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to disclose kernel memory. An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to disclose kernel memory.
References

Mon, 03 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Kernel Memory Disclosure via Information Leaking Vulnerability in macOS

Sun, 02 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Title Kernel Memory Information Leak in macOS

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Kernel Memory Information Leak in macOS
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An information leakage was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to disclose kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:30:29.991Z

Reserved: 2026-07-20T18:10:18.985Z

Link: CVE-2026-64744

cve-icon Vulnrichment

Updated: 2026-07-28T16:02:25.342Z

cve-icon NVD

Status : Modified

Published: 2026-07-27T21:17:13.283

Modified: 2026-08-17T22:17:20.013

Link: CVE-2026-64744

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T00:45:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor