Impact
An application may be able to access and leak sensitive kernel state, resulting in unauthorized disclosure of confidential information. The vulnerability exists because the system fails to validate that sensitive data is not exposed to unprivileged contexts. The impact is a loss of confidentiality for data residing in kernel memory.
Affected Systems
Apple’s iOS and iPadOS operating systems are affected for all versions released prior to iOS 18.7.10 and iPadOS 18.7.10, wherein the issue is addressed.
Risk and Exploitability
The CVSS score is not provided, and the EPSS score is unavailable; the vulnerability is not listed in CISA KEV. The likely attack vector is a local application that can read kernel state, inferred from the description that an app may trigger the leak. The risk remains low to moderate in the absence of published exploit evidence, but the potential to expose sensitive system data warrants precautionary action.
OpenCVE Enrichment