Impact
A logic problem in multiple Apple operating systems allows a remote attacker to trigger a denial‑of‑service. The weakness arises from insufficient checks within the system’s processing flow, which can be abused to crash or otherwise disable service functionality. The vulnerability is listed as a medium‑high severity issue with a CVSS score of 7.5, reflecting its potential to disrupt availability for affected devices.
Affected Systems
Apple devices running iOS 18.7.3, 26.2, iPadOS 18.7.3, 26.2, macOS Sequoia 15.7.4, Sonoma 14.8.4, Tahoe 26.2, visionOS 26.2, and watchOS 26.2 are impacted. All earlier releases of these operating systems are vulnerable until the specified patch versions are applied.
Risk and Exploitability
The EPSS score is less than 1 percent, indicating a low likelihood of public exploitation at present, and the vulnerability is not yet listed in CISA’s KEV catalog. However, the logic flaw can be triggered remotely, potentially via network‑connected services or malformed input. The medium‑high CVSS score underscores that, if exploited, the attacker could force the system into a state where services are unavailable, thereby degrading user experience and trust.
OpenCVE Enrichment