Impact
A flaw that allows type confusion between different memory object types was addressed by improved memory handling in Apple operating systems. The vulnerability can lead to an unexpected application termination when certain memory operations misinterpret the type of data being processed. The primary impact is a denial of service for the affected application, limiting functionality but not directly exposing sensitive data or system privileges.
Affected Systems
Apple’s iOS and iPadOS, macOS, tvOS, visionOS, and watchOS are affected. The bug has been patched in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, and watchOS 26.4.
Risk and Exploitability
The CVSS base score of 6.2 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of widespread exploitation. The flaw is not listed in the CISA KEV catalog. Exploitation would require an attacker to deliver input that triggers the type confusion, potentially through user‑initiated actions or malicious content processed by vulnerable applications. As it only causes a crash, the risk is limited to service disruption rather than data compromise.
OpenCVE Enrichment