Description
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to determine kernel memory layout.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure of kernel memory layout
Action: Apply Updates
AI Analysis

Impact

A memory initialization flaw allows an application to read uninitialized kernel memory, exposing the layout of the operating system’s memory. This information can serve as a foothold for further exploitation, potentially enabling attackers to craft more precise attacks against the device. The vulnerability does not directly grant code execution but provides the data required for targeted attacks on subsequent weaknesses.

Affected Systems

Apple iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27 are affected. The issue is fixed in the mentioned releases of each platform.

Risk and Exploitability

The EPSS score is < 1%, and the vulnerability is not listed in CISA’s KEV catalog, indicating a low public exploitation probability at present. Nonetheless, the information disclosure could dramatically lower the bar for future attacks if an attacker can discover the exact memory layout. The likely attack vector is a local application on the device, which can read kernel memory when the flaw is present. With a CVSS score of 5.5, the vulnerability falls into the moderate severity range. Once patched, the risk is eliminated.

Generated by OpenCVE AI on September 20, 2026 at 18:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update all Apple devices to the latest iOS, iPadOS, macOS, tvOS, visionOS, and watchOS releases that include the fix (i.e., 26.7/27 for iOS and iPadOS, 27 for macOS Golden Gate, 15.8 for Sequoia, 26.7 for Tahoe, 27 for tvOS, visionOS, and watchOS).
  • If a device cannot receive the update, restrict or remove applications that run with elevated privileges or otherwise have access to kernel memory until an official patch is available.
  • Continuously monitor Apple security advisories and apply new updates promptly as mitigations are issued for related kernel memory issues.

Generated by OpenCVE AI on September 20, 2026 at 18:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Title Kernel Memory Layout Disclosure via Uninitialized Memory in Apple Operating Systems

Wed, 16 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 16 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Title Kernel Memory Layout Disclosure via Uninitialized Memory in Apple Operating Systems

Wed, 16 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Title Kernel Memory Layout Disclosure via Improper Memory Initialization
Weaknesses CWE-200

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-457
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Title Kernel Memory Layout Disclosure via Improper Memory Initialization
Weaknesses CWE-200

Tue, 15 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to determine kernel memory layout.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T18:04:26.297Z

Reserved: 2026-07-22T00:46:56.740Z

Link: CVE-2026-65405

cve-icon Vulnrichment

Updated: 2026-09-15T18:04:15.579Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:24.083

Modified: 2026-09-16T18:42:55.293

Link: CVE-2026-65405

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T18:45:02Z

Weaknesses
  • CWE-457

    Use of Uninitialized Variable