
Kernel info leak Proof of Concept patched in iOS 26.4 / macOS 26.4
The vulnerability exists because the kernel implementation of tcp_sysctl_info performs a global lookup for the connection without verifying that the calling process either owns the socket or possesses elevated privileges like root.
An unprivileged attacker can obtain current 32 bit sequence numbers like SND.NXT & RCV.NXT including root or system daemons like apsd, trustd, cloudd