Impact
A type confusion vulnerability exists in multiple Apple operating systems where the system may interpret data as a different type. This flaw, identified as CWE‑843, can be triggered by a remote attacker who sends specially crafted input. When the vulnerability is exploited, the operating system may crash, resulting in a denial of service on the affected device.
Affected Systems
Apple environments impacted by this issue include iOS and iPadOS on iPhone and iPad, macOS Sequoia, macOS Sonoma, macOS Tahoe, tvOS, visionOS, and watchOS. The fix is included in iOS 18.7.9 and 26.5, iPadOS 18.7.9 and 26.5, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, and watchOS 26.5. Devices running any prior releases remain vulnerable until these updates are installed.
Risk and Exploitability
The CVSS score of 7.5 reflects a moderate severity of potential disruption. The EPSS score of < 1% indicates a very low probability of real‑world exploitation, and the vulnerability currently does not appear in CISA’s KEV catalog, suggesting no known active exploits. Based on the EPSS score and KEV status, the overall likelihood of exploitation is low, but a remote attacker could still cause service interruption if the device is running a vulnerable OS version.
OpenCVE Enrichment