Executive brief
iOS and iPadOS are mobile operating systems that power iPhones and iPads. A memory management flaw could allow an app to access sensitive kernel memory that should remain private. While the reported severity is low, kernel memory disclosure can expose system internals used by attackers to bypass security protections.
Technical details
This is an information disclosure vulnerability in iOS, iPadOS, and related Apple operating systems caused by improper memory management. The flaw allows a locally-installed application to read sensitive kernel memory that should be protected from user-space access. An attacker with the ability to run an app on the target device can exploit this to disclose kernel memory contents, which often contains security-sensitive data including Address Space Layout Randomization (ASLR) bypass information. No special privileges beyond app installation are required. The vulnerability is fixed in iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27.
Affected products
- Apple iOS before 27
- Apple iPadOS before 27
- Apple macOS Golden Gate before 27
- Apple macOS Tahoe before 26.7
- Apple tvOS before 27
- Apple visionOS before 27
- Apple watchOS before 27
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched