Impact
Improper initialization of kernel memory allows a root‑privileged application to read data that has not been set by the system, potentially exposing sensitive information from other processes or the kernel itself. The weakness is an uninitialized memory read, classified under CWE‑665, and the impact is information disclosure that can compromise confidentiality.
Affected Systems
Apple operating systems are affected. The issue is mitigated in iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27. Such versions replace the vulnerable code path that performed insufficient memory initialization.
Risk and Exploitability
Because the vulnerability can only be exploited by an application running with root privileges, it is unlikely to be used by external attackers without already having control over a privileged process. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, indicating limited known exploitation. Nonetheless, any root‑privileged app could read sensitive data from the kernel memory, so the potential confidentiality impact is high if such an app is malicious or compromised.
OpenCVE Enrichment