Impact
A race condition in Apple operating systems allows an application to induce an unexpected system termination, causing a denial of service. The weakness arises from insufficient validation implemented during concurrent operations, which is categorized under race condition weaknesses (CWE‑362).
Affected Systems
Affected Apple products include iOS, iPadOS, macOS, tvOS, and watchOS. Specific vulnerable releases are iOS 18.7.9 and 26.5, iPadOS 18.7.9 and 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, and watchOS 26.5.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score of <1% points to a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The description states that an application may trigger the race condition, implying that the attack requires a local or installed app; remote exploitation is not indicated by the current data.
OpenCVE Enrichment