Impact
The flaw is caused by insufficient redaction of sensitive data within the operating system’s kernel handling routines. When this weakness is exploited, a user‑space portion of kernel memory that should remain protected can be read. The resulting information‑disclosure vulnerability, classified as CWE-200, exposes highly privileged data that could enable attackers to learn confidential information, bypass isolation boundaries, or facilitate further exploits.
Affected Systems
Apple operating systems that had not yet incorporated the fix are impacted. This includes iOS versions before 26.6, iPadOS before 26.6, macOS Sequoia before 15.8, macOS Tahoe before 26.6, tvOS before 26.6, visionOS before 26.6, and watchOS before 26.6. Devices running any of these version numbers remain vulnerable until the appropriate update is installed.
Risk and Exploitability
The EPSS score is listed as less than 1%, and the vulnerability is not in CISA’s KEV catalog. The CVSS score of 3.3 indicates a low to moderate severity. The potential to read kernel memory can leak privileged data, but the likelihood of exploitation remains low, presumably requiring a trusted or elevated‑privilege application to trigger the flaw. Families not yet patched remain vulnerable until the update is applied. Monitoring and timely patching are recommended.
OpenCVE Enrichment