Executive brief
A security vulnerability in Apple's operating systems could allow a malicious application to discover the layout of the system's kernel memory. This information is typically used by attackers as a stepping stone to bypass security protections and perform more advanced attacks. Apple has released software updates for iPhone, iPad, Mac, Apple TV, and Apple Watch to address this issue.
Technical details
A vulnerability exists in the IOHIDFamily component of various Apple operating systems due to insufficient data redaction in system logs. By analyzing these logs, a local malicious application can determine the kernel memory layout, effectively bypassing Kernel Address Space Layout Randomization (KASLR). This information disclosure is often a prerequisite for more severe kernel-level exploits. The issue was resolved by improving the redaction of sensitive data within the logging mechanism. Patches are available in iOS 18.7.9, iOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, and corresponding versions of iPadOS, tvOS, and watchOS.
Affected products
- Apple iOS Before 18.7.9, before 26.5
- Apple iPadOS Before 18.7.9, before 26.5
- Apple macOS Sequoia Before 15.7.7
- Apple macOS Sonoma Before 14.8.7
- Apple macOS Tahoe Before 26.5
- Apple tvOS Before 26.5
- Apple watchOS Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched
- 2026-05-11: advisory