CVE-2026-49269Active Exploitation

LOWCVSS 8.6 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Apple M1 GPUs retain register file data between compute shader dispatches from different processes. A sandboxed Metal attacker app can run a GPU reader shader that reads stale register values left by a separate sandboxed victim app. In the proof of concept, GPUVictim.app generates a fresh random 128-bit secret using SecRandomCopyBytes and loads it into GPU registers. GPUAttacker.app, a separate sandboxed app, recovers the exact secret from stale GPU register state. NOTE: The vendor stated that this behavior affects only legacy hardware and has already been addressed at the hardware level in current-generation Apple Silicon.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-24: 1Active Exploitation · 2026-06-24: 1Technical Details · 2026-06-24: 106-24
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Kaitan ID Security@KaitanSecurity
    Active Exploitation

    ⚠️ HIGH — CVE-2026-49269 Apple M1 GPUs retain register file data between compute shader dispatches from different processes. A sandboxed Metal a… CVSS 8.6 ⚡ Exploit in the wild Full analysis → https://sec.kaitan.id/cves/CVE-2026-49269 #Apple #CyberSecurity #InfoSec

    Post summary

    CVE-2026-49269, a data‑leakage flaw in Apple M1 GPUs with CVSS 8.6, is reported to be actively exploited in the wild, though no proof of concept, exploit code, or patch information is provided.

    0001047
    82 followersView on X

Explore more