Impact
An application can trigger a memory handling flaw that may lead to unexpected system termination or corruption of kernel memory. The vulnerability is a buffer overflow described by CWE‑119 and CWE‑787, which allows overwriting memory regions and potentially corrupting critical system structures. This can cause the device to crash or exhibit unstable behavior, impacting availability and integrity of the operating system.
Affected Systems
The flaw affects Apple iOS, iPadOS, macOS, tvOS, visionOS and watchOS. Versions prior to 26.4 are vulnerable, while iOS 26.4, iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4 and watchOS 26.4 include the fix.
Risk and Exploitability
The CVSS score of 5.5 indicates a medium severity. With an EPSS score of less than 1 % and no listing in KEV, the likelihood of exploitation is currently low, but the impact if exploited is significant. Based on the description, a malicious or compromised application could exploit the flaw locally to corrupt kernel memory or force a system crash.
OpenCVE Enrichment