Description
The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to disclose kernel memory.
Published: 2026-07-27
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from insufficient bounds checking in a kernel component, enabling an application to read beyond its intended memory boundaries. This permits an attacker to obtain sensitive kernel data, potentially exposing confidential information and facilitating further escalation. The flaw is classified as a memory disclosure weakness.

Affected Systems

Apple macOS is affected, with the issue resolved in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6. Any system running a previous version of these macOS releases is at risk.

Risk and Exploitability

The CVSS score is 5.5, indicating moderate severity, and the EPSS score is less than 1%, suggesting a low probability of exploitation. The vulnerability is not in CISA's KEV catalog. Based on the description, the likely attack vector is local via a compromised application that can trigger the kernel bounds check failure; no publicly known remote exploitation has been documented.

Generated by OpenCVE AI on August 4, 2026 at 13:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade macOS to Sequoia 15.7.8 or later
  • Upgrade macOS to Sonoma 14.8.8 or later
  • Upgrade macOS to Tahoe 26.6 or later

Generated by OpenCVE AI on August 4, 2026 at 13:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title Kernel Memory Disclosure via Improper Bounds Checks in macOS

Tue, 28 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Kernel Memory Disclosure via Improper Bounds Checks in macOS
Weaknesses CWE-125

Tue, 28 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to disclose kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T15:52:25.405Z

Reserved: 2026-07-20T18:10:53.025Z

Link: CVE-2026-64776

cve-icon Vulnrichment

Updated: 2026-07-28T15:52:01.914Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:15.620

Modified: 2026-07-28T17:59:37.613

Link: CVE-2026-64776

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:15:03Z

Weaknesses