Impact
The vulnerability arises from improper input validation (CWE‑20). An application that triggers the flaw can corrupt kernel memory or cause the entire system to terminate unexpectedly, resulting in loss of availability and potential integrity compromise on the affected device.
Affected Systems
Apple iOS, iPadOS, and macOS devices running a system version older than 26.5.2 are vulnerable. The fix is delivered with the 26.5.2 releases for each platform.
Risk and Exploitability
The CVSS score of 9.1 indicates a critical severity, while the EPSS score of < 1% suggests a low probability of exploitation in the wild. The flaw can be leveraged only by an application that runs on the device, implying a local exploitation scenario. The vulnerability is not listed in the CISA KEV catalog, and there is no evidence of remote or privilege‑escalation capabilities in the description.
OpenCVE Enrichment