CVE-2026-84530(apple / ipados)

LOWCVSS 3.3 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An information disclosure issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to disclose kernel memory.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • tvos

Threat summary

  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 3 mentions (2026-09-22); latest day: 3
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
ipadosiphone_osmacostvosvisionoswatchos

Deep dive

Activity timeline6 mentions / 2d
01223Mentions · 2026-09-22: 3Mentions · 2026-09-23: 309-2209-23
Referenced assets3 URLs
Full discourse6 posts
  • Vladislav Shevchenko@destr4ctt

    Finally got around to writing up CVE-2026-84530, which was fixed in the iOS 27 security release This one is a kernel address leak in AIO subsystem - aio_workq_entry pointer gets left in kqueue metadata and can be read back from userspace More details: https://github.com/vschko/CaseStudies/tree/main/CVE-2026-84530 https://t.co/KQ4uVdQtBl

    3230131658.8K
    441 followersView on X
  • !Manan@0xManan

    iOS 27 just patched a clean kernel address leak. CVE-2026-84530 : the AIO subsystem leaves an aio_workq_entry pointer sitting in kqueue metadata. userspace can read it right back. no corruption needed, just a leftover kernel pointer handed to you on a platter. useful primitive for anyone building bigger chains. fixed in the latest iOS 27 security release. Full write-up by @destr4ctt : https://github.com/vschko/CaseStudies/tree/main/CVE-2026-84530 #iOS #ExploitDev #CVE

    16040194.0K
    2.1K followersView on X
  • Mr.Niko@_MrNiko

    🚨 CVE-2026-84530 iOS kernel pointer leak AIO kqueue hands you an aio_workq_entry address. aio_register_kevent puts entryp in http://kev.data. kevent_register copies it into kn_sdata. filt_aioattach stores it in kn_hook and never clears kn_sdata. EXTINFO zeroes kqext_kev.data. kqext_sdata still prints the kernel address. fixed on iOS 27. writeup + PoC: https://github.com/vschko/CaseStudies/tree/main/CVE-2026-84530 credit: vschko #iOS #ExploitDev #InfoSec

    25026222.3K
    1.3K followersView on X
  • habib@hbeeb2001

    النطاق الشامل والدقيق لجميع الثغرات المكتشفة والمطروحة حالياً بتاريخ اليوم 23/09/2026 مع اكتاشف تغرة جديدك ثغرة تسريب عناوين النواة النظيفة (⁠CVE-2026-84530⁠): يغطي إصدارات نظام التشغيل من iOS 26.0 وحتى iOS 26.6، وذلك على النحو التالي:

    6000076
    195 followersView on X
  • habib@hbeeb2001

    - ثغرة تسريب عناوين النواة النظيفة (⁠CVE-2026-84530⁠): المفهوم: ثغرة قراءة مباشرة في البيانات الوصفية لـ AIO تسمح بنقل عناوين ذاكرة النواة بوضوح إلى مساحة المستخدم بدون أحداث إتلاف للذاكرة، مما يكسر حماية KASLR التشفيرية بسهولة.

    1000029
    195 followersView on X
  • habib@hbeeb2001

    *-بالنسبة للأجهزة الأحدث من معالج A14 فما فوق (مثل iPhone 12, 13, 14, 15, 16) تستفيد من ثغرات النواة الثلاث(⁠CVE-2026-84530⁠, ⁠CVE-2026-65343⁠, ⁠CVE-2026-64788⁠) وتفتقد لثغرة الإقلاع العتادية ⁠usbliter8⁠؛ النسبة المكتملة الأجهزة هو 55%، والنسبة المتبقية لها هي 45%

    0000018
    195 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSappletvos---
OSapplevisionos---
OSapplewatchos---

Explore more