Impact
A memory initialization flaw allows an application to read uninitialized kernel memory, exposing the layout of the operating system’s memory. This information can serve as a foothold for further exploitation, potentially enabling attackers to craft more precise attacks against the device. The vulnerability does not directly grant code execution but provides the data required for targeted attacks on subsequent weaknesses.
Affected Systems
Apple iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27 are affected. The issue is fixed in the mentioned releases of each platform.
Risk and Exploitability
The EPSS score is < 1%, and the vulnerability is not listed in CISA’s KEV catalog, indicating a low public exploitation probability at present. Nonetheless, the information disclosure could dramatically lower the bar for future attacks if an attacker can discover the exact memory layout. The likely attack vector is a local application on the device, which can read kernel memory when the flaw is present. With a CVSS score of 5.5, the vulnerability falls into the moderate severity range. Once patched, the risk is eliminated.
OpenCVE Enrichment