Impact
The CVE describes a flaw in memory‑management handling on Apple operating systems that allows an application to read from kernel memory. This vulnerability enables the disclosure of kernel memory, which results in an information disclosure of sensitive internal system data.
Affected Systems
Exact affected versions are not listed in the CVE, but the flaw exists in releases prior to the updates described in the fix: iOS 26.7, iPadOS 26.7, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27. Devices running any of the affected operating systems before those versions are considered vulnerable.
Risk and Exploitability
The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalogue, indicating a very low likelihood of exploitation. The CVSS score is 3.3, indicating a low but non‑negligible severity. The vulnerability allows an application to read kernel memory, which can expose internal system data. The attack vector is local via an application, as the issue requires an app to read kernel memory. No remote exploitation is documented.
OpenCVE Enrichment