Description
An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to leak sensitive kernel state.
Published: 2026-08-17
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure (CWE-200)
Action: Immediate Patch
AI Analysis

Impact

An information leakage vulnerability (CWE-200) has been addressed by adding validation because the system did not adequately restrict unprivileged contexts from accessing kernel state. The flaw permits a local application to read or expose sensitive kernel memory, potentially leading to unauthorized disclosure of confidential information. The issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27.

Affected Systems

Apple’s iOS, iPadOS, macOS, tvOS, visionOS, and watchOS operating systems are affected for all versions released prior to iOS 18.7.10 and iPadOS 18.7.10, iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27, wherein the issue is addressed.

Risk and Exploitability

The CVSS score is 5.5, and the EPSS score is < 1 %; the vulnerability is not listed in CISA KEV. The likely attack vector is a local application that can read kernel state, inferred from the description that an app may trigger the leak. The risk remains low to moderate in the absence of published exploit evidence, but the potential to expose sensitive system data warrants precautionary action.

Generated by OpenCVE AI on September 21, 2026 at 06:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all Apple devices to the latest available OS versions, such as iOS 18.7.10/iPadOS 18.7.10, iOS 27/iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27
  • Review and revoke unnecessary app permissions that access sensitive kernel data
  • Configure device management to flag or block applications attempting local data exfiltration and monitor system logs for anomalous activity

Generated by OpenCVE AI on September 21, 2026 at 06:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Title Local Application May Leak Sensitive Kernel State

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. An app may be able to leak sensitive kernel state. An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to leak sensitive kernel state.
References

Tue, 18 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Tue, 18 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Title Kernel State Information Leakage in iOS and iPadOS

Tue, 18 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Vendors & Products Apple
Apple ios And Ipados

Mon, 17 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Kernel State Information Leakage in iOS and iPadOS
Weaknesses CWE-200

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. An app may be able to leak sensitive kernel state.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-14T20:51:53.708Z

Reserved: 2026-07-20T18:10:30.633Z

Link: CVE-2026-64760

cve-icon Vulnrichment

Updated: 2026-08-18T12:55:45.698Z

cve-icon NVD

Status : Modified

Published: 2026-08-17T22:17:20.937

Modified: 2026-09-14T21:17:15.097

Link: CVE-2026-64760

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T07:00:08Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor