Executive brief
iOS and iPadOS contain a memory initialization vulnerability that allows apps running with elevated privileges to read uninitialized kernel memory. This could expose sensitive system information, cryptographic keys, or other confidential data that should remain protected. Apple has addressed this issue with improved memory handling in recent OS updates.
Technical details
A memory initialization flaw in iOS and iPadOS kernel code fails to properly initialize heap or stack memory before use, allowing information disclosure. The vulnerability requires the attacking app to have root-level privileges, which is an unusual precondition but possible through privilege escalation chains or on jailbroken devices. An attacker can read uninitialized kernel memory regions to leak sensitive data such as cryptographic keys, addresses (defeating ASLR), or other privileged information. The fix involves improved memory handling and initialization. No evidence of active exploitation in the wild has been reported.
Affected products
- Apple iOS before 27
- Apple iPadOS before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
- Apple macOS Golden Gate 27
- Apple tvOS before 27
- Apple visionOS before 27
- Apple watchOS before 27
Timeline
- 2026-09-14: disclosed: CVE-2026-84622 published and security updates released
- 2026-09-14: patched: Fixed in iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27