Impact
The vulnerability involves improper memory handling in the Apple kernel layers, potentially allowing an attacker to cause unexpected system termination or read kernel memory. The issue is fixed in multiple Apple operating systems, including iOS 26.4, iPadOS 26.4, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, and watchOS 26.4.
Affected Systems
Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS devices are impacted. The vulnerability is resolved in the aforementioned firmware releases; devices running earlier versions of any of these operating systems remain vulnerable.
Risk and Exploitability
The CVSS score is 7.7, indicating a high severity, while the EPSS score is below 1%, suggesting a low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The attack vector is not explicitly stated in the advisory; it is inferred that a local attacker with elevated privileges would need to exploit a kernel memory handling flaw to trigger the crash or memory read. Despite the low probability, the potential for kernel memory exposure or unexpected termination warrants timely patching.
OpenCVE Enrichment