Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Apple Products Memory Initialization Vulnerability Allowing Kernel Memory Disclosure

Vulnerability

A memory initialization vulnerability has been identified in the XNU kernel, affecting multiple Apple operating systems, including macOS Big Sur, High Sierra, Mojave, iOS 12.4.9, iOS 14.2, iPadOS 14.2, and watchOS 6.2.9. This vulnerability may allow a malicious application to disclose kernel memory, with reports of an active exploit.

Impact

Exploitation of this vulnerability allows for unauthorized disclosure of kernel memory, which could be leveraged for further attacks, such as arbitrary code execution with kernel privileges.

Remediation

Users can update to macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2, iPadOS 14.2, or watchOS 5.3.9. Instructions for updating can be found on the Apple Support website.

Added: May 15, 2026, 10:44 AM
Updated: May 15, 2026, 10:44 AM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
5.0
remediation
7.7
relevance
0.0
threat
8.9
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.