Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Apple XNU Kernel Type Confusion Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A type confusion vulnerability has been identified in the XNU kernel's turnstile management, which could allow a malicious application to execute arbitrary code with kernel privileges. This vulnerability affects multiple Apple operating systems, including macOS Big Sur, High Sierra, Mojave, iOS 12, iOS 14, iPadOS 14, and various versions of watchOS. The issue arises from improper state handling, which has been addressed in the latest updates for each affected platform.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of code with kernel privileges, potentially allowing for system-level access and control.

Remediation

Users can update to the latest version of macOS, iOS, iPadOS, or watchOS to address this vulnerability. Specific update instructions can be found on the Apple Support website.

Added: May 15, 2026, 10:41 AM
Updated: May 15, 2026, 10:41 AM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
7.5
exploitability
5.3
remediation
7.7
relevance
0.0
threat
8.3
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.