Description
An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. An app may be able to leak sensitive kernel state.
Published: 2026-08-17
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An application may be able to access and leak sensitive kernel state, resulting in unauthorized disclosure of confidential information. The vulnerability exists because the system fails to validate that sensitive data is not exposed to unprivileged contexts. The impact is a loss of confidentiality for data residing in kernel memory.

Affected Systems

Apple’s iOS and iPadOS operating systems are affected for all versions released prior to iOS 18.7.10 and iPadOS 18.7.10, wherein the issue is addressed.

Risk and Exploitability

The CVSS score is not provided, and the EPSS score is unavailable; the vulnerability is not listed in CISA KEV. The likely attack vector is a local application that can read kernel state, inferred from the description that an app may trigger the leak. The risk remains low to moderate in the absence of published exploit evidence, but the potential to expose sensitive system data warrants precautionary action.

Generated by OpenCVE AI on August 17, 2026 at 23:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update all devices to iOS 18.7.10 or iPadOS 18.7.10
  • Review and revoke unnecessary app permissions that access sensitive kernel data
  • Configure device management to flag or block applications attempting local data exfiltration and monitor system logs for anomalous activity

Generated by OpenCVE AI on August 17, 2026 at 23:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 18 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Vendors & Products Apple
Apple ios And Ipados

Mon, 17 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Kernel State Information Leakage in iOS and iPadOS
Weaknesses CWE-200

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. An app may be able to leak sensitive kernel state.
References

Subscriptions

Apple Ios And Ipados
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:31:35.899Z

Reserved: 2026-07-20T18:10:30.633Z

Link: CVE-2026-64760

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T22:17:20.937

Modified: 2026-08-17T22:17:20.937

Link: CVE-2026-64760

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T23:45:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor