Description
An information disclosure issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to disclose kernel memory.
Published: 2026-09-14
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure of kernel memory
Action: Apply update
AI Analysis

Impact

The CVE describes a flaw in memory‑management handling on Apple operating systems that allows an application to read from kernel memory. This vulnerability enables the disclosure of kernel memory, which results in an information disclosure of sensitive internal system data.

Affected Systems

Exact affected versions are not listed in the CVE, but the flaw exists in releases prior to the updates described in the fix: iOS 26.7, iPadOS 26.7, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27. Devices running any of the affected operating systems before those versions are considered vulnerable.

Risk and Exploitability

The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalogue, indicating a very low likelihood of exploitation. The CVSS score is 3.3, indicating a low but non‑negligible severity. The vulnerability allows an application to read kernel memory, which can expose internal system data. The attack vector is local via an application, as the issue requires an app to read kernel memory. No remote exploitation is documented.

Generated by OpenCVE AI on September 20, 2026 at 19:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the operating system to the latest firmware that contains the memory‑management fix (iOS 26.7 or newer, iPadOS 26.7 or newer, macOS Golden Gate 27 or newer, macOS Tahoe 26.7 or newer, tvOS 27 or newer, visionOS 27 or newer, or watchOS 27 or newer).
  • Install applications only from the official App Store or approved enterprise catalogs to reduce the likelihood that a malicious app could exploit this flaw.
  • Monitor the device for anomalous application behavior and enforce strict sandboxing to prevent privileged operations that could access kernel memory.

Generated by OpenCVE AI on September 20, 2026 at 19:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Title Kernel Memory Information Disclosure via Improper Memory Management on Apple Operating Systems

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Information Disclosure via Kernel Memory Access in Apple Operating Systems
Weaknesses CWE-200

Tue, 15 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title Information Disclosure via Kernel Memory Access in Apple Operating Systems
Weaknesses CWE-200

Tue, 15 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An information disclosure issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to disclose kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T16:56:52.050Z

Reserved: 2026-09-01T21:13:17.750Z

Link: CVE-2026-84530

cve-icon Vulnrichment

Updated: 2026-09-17T16:56:43.446Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:29.417

Modified: 2026-09-18T17:36:04.877

Link: CVE-2026-84530

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:00:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor