Impact
The vulnerability is a memory handling flaw that can allow an application to trigger an unexpected system termination. The flaw involves improper buffer handling, as indicated by its mapping to CWE‑119. The crash leads to loss of availability for the device, but the description does not indicate that any sensitive data is disclosed or that the flaw can be leveraged for further compromise.
Affected Systems
Apple devices running iOS, iPadOS, macOS, tvOS, visionOS, or watchOS versions earlier than 26.3 are affected. The issue is resolved in iOS 26.3, iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, and watchOS 26.3.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while an EPSS score below 1% suggests a low probability of exploitation. The description does not specify an attack surface, but it implies that an application capable of misusing memory could cause a crash. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation at this time.
OpenCVE Enrichment