Impact
A remote attacker can trigger an unexpected termination of applications running on Apple iOS or iPadOS. The issue was addressed with improved checks in later releases, implying that a flaw in resource handling caused the crash. The vulnerability is mapped to CWE‑400, which indicates an unchecked resource exhaustion condition; this connection is inferred from the CWE reference rather than directly stated in the description.
Affected Systems
Devices operating on Apple iOS or iPadOS versions earlier than 26.4 are affected. The flaw can cause any application running on those earlier operating systems to terminate unexpectedly, potentially disrupting user workflows and dependent services.
Risk and Exploitability
The CVSS score of 7.5 classifies the vulnerability as high severity, yet the EPSS score is reported as under 1 %, suggesting a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Because the description explicitly states that a remote attacker may cause the crash, the attack vector is remote, and the impact is limited to application availability rather than broader system compromise.
OpenCVE Enrichment