Impact
A type confusion flaw, where objects are misinterpreted as another type, can cause memory handling errors during operation. An attacker that can supply or influence a misinterpreted object could trigger a crash or other unintended shutdown, resulting in denial of service. The weakness is classified as CWE‑843, which impacts the integrity of memory usage and can lead to application-level failures.
Affected Systems
Apple devices running iOS or iPadOS versions earlier than 18.7 or 26, macOS operating systems before Sequoia 15.7, Sonoma 14.8 or Tahoe 26, and all tvOS, visionOS, and watchOS versions before 26 are susceptible. All Apple operating systems enumerated in the affected‑cpe list are impacted if they have not received the corresponding update.
Risk and Exploitability
The CVSS score of 5.5 marks the flaw as medium severity, reflecting that its impact is limited to service availability rather than privilege escalation. EPSS is below 1 %, indicating a low but non‑negligible likelihood of exploitation. The vulnerability is not catalogued in CISA’s KEV list, so no active exploitation reports are publicly known. The attack vector is inferred to be local or app‑based, as the description references an app that can trigger the denial‑of‑service event. No elevated privileges or network-level access are required, so the risk is moderate but still warrants timely patching.
OpenCVE Enrichment
EUVD