Impact
A race condition exists that can cause the operating system to terminate unexpectedly, resulting in a denial of service. The weakness is a classic race condition (CWE‑362) where improper state handling allows a malicious or misbehaving application to trigger system termination. The impact is a loss of availability for the impacted device, potentially interrupting critical processes and user sessions.
Affected Systems
Apple macOS versions prior to macOS Sequoia 15.6, macOS Sonoma 14.7.7, and macOS Ventura 13.7.7 are affected. The vulnerability is present in all operating system builds that lack the improved state‑handling fix described in the CVE. Users running any of these unsupported releases are at risk.
Risk and Exploitability
The CVSS base score of 9.8 indicates a severe risk, while the EPSS score of less than 1% suggests low current exploit probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local or system‑level, as the race condition requires interaction with specific system components. The exploit, however, could be triggered by a malicious application or by abuse of legitimate applications that invoke the vulnerable code paths.
OpenCVE Enrichment
EUVD