
Finally got around to writing up CVE-2026-84530, which was fixed in the iOS 27 security release This one is a kernel address leak in AIO subsystem - aio_workq_entry pointer gets left in kqueue metadata and can be read back from userspace More details: https://github.com/vschko/CaseStudies/tree/main/CVE-2026-84530 https://t.co/KQ4uVdQtBl



