Impact
An out‑of‑bounds memory read can trigger unexpected termination of the entire system. The flaw arises from insufficient bounds checking in a core component and may allow a malicious application to cause the device to crash when it attempts to access data beyond its allocated range.
Affected Systems
The vulnerability affects every Apple operating system, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. All versions before the 26.0 release are susceptible, while the issue is fixed in iOS 26, iPadOS 26, macOS 26, tvOS 26, visionOS 26, and watchOS 26.
Risk and Exploitability
The CVSS score is 3.3 and the EPSS score is less than 1 %. The vulnerability is not listed in CISA’s KEV catalog, indicating no known active exploitation. Based on the description, it is inferred that the attack vector is local, needing a malicious app installed on the device. An attacker with access to install applications could trigger a crash but does not gain code execution or data exfiltration capabilities.
OpenCVE Enrichment
EUVD