Impact
An invalid input check caused an out‑of‑bounds read in the operating system kernel, which may allow an application to read sensitive kernel memory. The vulnerability does not provide immediate execution of code, but the disclosed data could assist an attacker in building more advanced attacks. The problem is specifically an overflow that lets the code read beyond a defined buffer boundary, exposing confidential information.
Affected Systems
Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are all affected. Versions prior to the public release of the iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27 builds contain the issue; the fix is included in these 27 releases and later.
Risk and Exploitability
The EPSS is not available and the vulnerability is not listed in CISA KEV, so a precise exploitation probability cannot be quantified. Based on the description, the likely attack vector is a compromised or malicious application that can trigger the out‑of‑bounds read and obtain kernel data. Since the flaw involves reading kernel memory, the impact can contribute to confidentiality breaches and may support future attacks that require kernel information. The lack of an available CVSS score means the concrete severity is undefined, but the potential for sensitive data leakage warrants prompt action.
OpenCVE Enrichment