Executive brief
A security vulnerability in Apple's operating systems could allow a malicious application to access sensitive internal information about the system's core (the kernel). This type of data leak can be used by attackers to bypass security protections and facilitate more complex attacks. The issue has been resolved in the latest software updates for iPhone, iPad, Mac, Apple TV, and Apple Watch.
Technical details
A logging issue in the Apple Kernel was identified where sensitive kernel state was not properly redacted. This vulnerability allows a locally installed malicious application to read sensitive kernel memory information from system logs. Such information disclosure is often used to defeat Address Space Layout Randomization (ASLR) or other exploit mitigations, facilitating further privilege escalation. The root cause was insufficient data redaction in the kernel's logging mechanisms. Apple addressed this by improving redaction logic across multiple operating systems including iOS, macOS, and watchOS.
Affected products
- Apple iOS Before 18.7.9, before 26.5
- Apple iPadOS Before 18.7.9, before 26.5
- Apple macOS Sequoia Before 15.7.7
- Apple macOS Sonoma Before 14.8.7
- Apple macOS Tahoe Before 26.5
- Apple tvOS Before 26.5
- Apple watchOS Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched
- 2026-05-11: advisory