Executive brief
A security vulnerability in macOS could allow a malicious application to access sensitive information about the operating system's core (the kernel). This type of leak can be used by attackers to bypass security protections and gain deeper access to the system. Apple has released software updates to address this issue by improving how sensitive data is hidden from applications.
Technical details
An information disclosure vulnerability exists in the macOS kernel where sensitive state information is not properly redacted. A locally installed malicious application could exploit this to leak kernel memory addresses or other sensitive internal states, potentially facilitating the bypass of Address Space Layout Randomization (ASLR) or other kernel-level protections. The vulnerability was addressed through improved redaction of sensitive information. Affected versions include macOS Sequoia before 15.7.8, macOS Sonoma before 14.8.8, and macOS Tahoe before 26.6.
Affected products
- Apple macOS Sequoia Before 15.7.8
- Apple macOS Sonoma Before 14.8.8
- Apple macOS Tahoe Before 26.6
Timeline
- 2026-07-27: advisory
- 2026-07-27: disclosed
- 2026-07-27: patched