Impact
The vulnerability is a use‑after‑free flaw that can trigger an unexpected system termination when a malicious app exploits improper memory management. Based on the description, it is inferred that the attack vector is a malicious application executing on the target system. An attacker may cause a crash that disrupts availability without providing direct data or code‑execution capabilities.
Affected Systems
Apple iOS 18.7.9 and 26.5, iPadOS 18.7.9 and 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5 are affected.
Risk and Exploitability
The vulnerability has a CVSS score of 7.5 and an EPSS score of < 1%, indicating a very low probability of exploitation. Based on the description, the attack vector is a malicious application that can execute on the target system. A successful exploitation would lead to a denial‑of‑service condition by terminating system services or the entire OS. Although it is not listed in CISA's KEV catalog, the combined CVSS and low EPSS suggest a low exploitation probability.
OpenCVE Enrichment