Description
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to disclose kernel memory.
Published: 2026-09-14
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Memory Disclosure
Action: Apply Patch
AI Analysis

Impact

The flaw is caused by insufficient redaction of sensitive data within the operating system’s kernel handling routines. When this weakness is exploited, a user‑space portion of kernel memory that should remain protected can be read. The resulting information‑disclosure vulnerability, classified as CWE-200, exposes highly privileged data that could enable attackers to learn confidential information, bypass isolation boundaries, or facilitate further exploits.

Affected Systems

Apple operating systems that had not yet incorporated the fix are impacted. This includes iOS versions before 26.6, iPadOS before 26.6, macOS Sequoia before 15.8, macOS Tahoe before 26.6, tvOS before 26.6, visionOS before 26.6, and watchOS before 26.6. Devices running any of these version numbers remain vulnerable until the appropriate update is installed.

Risk and Exploitability

The EPSS score is listed as less than 1%, and the vulnerability is not in CISA’s KEV catalog. The CVSS score of 3.3 indicates a low to moderate severity. The potential to read kernel memory can leak privileged data, but the likelihood of exploitation remains low, presumably requiring a trusted or elevated‑privilege application to trigger the flaw. Families not yet patched remain vulnerable until the update is applied. Monitoring and timely patching are recommended.

Generated by OpenCVE AI on September 20, 2026 at 19:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest Apple OS update that incorporates the kernel memory disclosure fix.
  • Limit the installation and use of third‑party applications that request or run with elevated privileges to reduce opportunities to trigger the flaw.
  • Monitor Apple support and security advisories for any interim mitigations or guidance while the patch is pending.

Generated by OpenCVE AI on September 20, 2026 at 19:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Title Kernel Memory Disclosure via Improper Redaction in Apple OS

Fri, 18 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Title Kernel Memory Disclosure due to Improper Redaction in Apple OS
Weaknesses CWE-200

Tue, 15 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Kernel Memory Disclosure due to Improper Redaction in Apple OS
Weaknesses CWE-200

Tue, 15 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to disclose kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T15:57:46.611Z

Reserved: 2026-07-22T00:46:16.023Z

Link: CVE-2026-65371

cve-icon Vulnrichment

Updated: 2026-09-17T15:57:40.075Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:21.700

Modified: 2026-09-18T14:40:34.883

Link: CVE-2026-65371

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:00:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor