Impact
This vulnerability is an out‑of‑bounds write that lets a malicious application write data outside the intended memory bounds, which can cause unexpected system termination or corrupt kernel memory, thereby breaking system, iPadOS, macOS, tvOS, visionOS and watchOS releases before iOS 26.7 or iPadOS 26.7, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27 are affected.
Affected Systems
The vulnerability affects Apple iOS and iPadOS versions before 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27. The issue is present in Apple platforms iOS, iPadOS, macOS, tvOS, visionOS, and watchOS across the specified versions.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while the EPSS score of < 1 % suggests a low likelihood of mass exploitation. The vulnerability is not listed in CISA’s KEV catalog. Nevertheless, if an attacker delivers a crafted app or malicious payload, the possibility of kernel memory corruption represents a high‑severity consequence. The likely attack vector is an application running with user privileges on the device.
OpenCVE Enrichment