Impact
The CVE description states that an application can trigger improper memory handling in Apple operating systems, potentially causing kernel memory corruption or unexpected system termination. This flaw may destabilize device operation or allow an attacker to corrupt critical kernel data structures, thereby affecting confidentiality, integrity, or availability of the entire system. The impact is thus severe, as kernel corruption can lead to privilege escalation or complete system compromise.
Affected Systems
Apple’s iOS, iPadOS, macOS, tvOS, visionOS, and watchOS versions prior to the patch releases iOS 26.6.1, iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, and watchOS 27 are potentially affected.
Risk and Exploitability
The CVSS score is not provided, and the EPSS score is not available, indicating no publicly known high exploitation probability. The flaw is not listed in the CISA KEV catalog. Based on the description, the vulnerability appears to be exploitable by a local application that executes the faulty memory handling path, suggesting a local attacker could trigger the flaw. While the exact exploit conditions are not detailed, the potential for kernel corruption or system crash warrants prompt attention.
OpenCVE Enrichment