Description
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app with root privileges may be able to read uninitialized kernel memory.
Published: 2026-09-14
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure via Uninitialized Kernel Memory Read
Action: Apply Patch
AI Analysis

Impact

Improper initialization of kernel memory allows a root‑privileged application to read data that has not been set by the system, potentially exposing sensitive information from other processes or the kernel itself. The weakness is an uninitialized memory read, classified under CWE‑665, and the impact is information disclosure that can compromise confidentiality.

Affected Systems

Apple operating systems are affected. The issue is mitigated in iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27. Such versions replace the vulnerable code path that performed insufficient memory initialization.

Risk and Exploitability

Because the vulnerability can only be exploited by an application running with root privileges, it is unlikely to be used by external attackers without already having control over a privileged process. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, indicating limited known exploitation. Nonetheless, any root‑privileged app could read sensitive data from the kernel memory, so the potential confidentiality impact is high if such an app is malicious or compromised.

Generated by OpenCVE AI on September 16, 2026 at 11:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update all affected Apple operating systems to the latest releases that contain the fix (iOS 26.7/27, iPadOS 26.7/27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27).
  • Restrict root privileges to essential system components and revoke such privileges from third‑party or untrusted applications.
  • Audit installed applications with root access and remove or reconfigure those that do not require such privileges.

Generated by OpenCVE AI on September 16, 2026 at 11:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-908
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Uninitialized Kernel Memory Read in Apple Operating Systems
Weaknesses CWE-665

Tue, 15 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app with root privileges may be able to read uninitialized kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T15:34:13.554Z

Reserved: 2026-09-01T21:13:23.286Z

Link: CVE-2026-84622

cve-icon Vulnrichment

Updated: 2026-09-17T15:33:55.724Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:37.177

Modified: 2026-09-18T14:57:23.220

Link: CVE-2026-84622

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T11:30:12Z

Weaknesses
  • CWE-665

    Improper Initialization

  • CWE-908

    Use of Uninitialized Resource