Impact
The vulnerability is a use‑after‑free flaw that has been partially mitigated by Apple with enhanced memory management. However, earlier releases remain affected and an application can induce unexpected system termination. An attacker can trigger the failure by executing a malicious app on the device, which results in a denial‑of‑service condition without exposing data or allowing code execution.
Affected Systems
Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS releases prior to iOS 18.7.9, iOS 26.5, iOS 27, iPadOS 18.7.9, iPadOS 26.5, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.7, macOS Sequoia 15.8, macOS Sonoma 14.8.7, macOS Tahoe 26.5, macOS Tahoe 26.7, tvOS 26.5, tvOS 27, visionOS 26.5, visionOS 27, and watchOS 26.5, watchOS 27.
Risk and Exploitability
The vulnerability has a CVSS score of 7.5 and an EPSS score of < 1%, indicating a very low probability of exploitation. Based on the description, the attack vector is a malicious application that can execute on the target system. A successful exploitation would lead to a denial‑of‑service condition by terminating system services or the entire OS. Although it is not listed in CISA's KEV catalog, the combined CVSS and low EPSS suggest a low exploitation probability.
OpenCVE Enrichment