Impact
An information leakage vulnerability (CWE-200) has been addressed by adding validation because the system did not adequately restrict unprivileged contexts from accessing kernel state. The flaw permits a local application to read or expose sensitive kernel memory, potentially leading to unauthorized disclosure of confidential information. The issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27.
Affected Systems
Apple’s iOS, iPadOS, macOS, tvOS, visionOS, and watchOS operating systems are affected for all versions released prior to iOS 18.7.10 and iPadOS 18.7.10, iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27, wherein the issue is addressed.
Risk and Exploitability
The CVSS score is 5.5, and the EPSS score is < 1 %; the vulnerability is not listed in CISA KEV. The likely attack vector is a local application that can read kernel state, inferred from the description that an app may trigger the leak. The risk remains low to moderate in the absence of published exploit evidence, but the potential to expose sensitive system data warrants precautionary action.
OpenCVE Enrichment