Impact
The vulnerability arises from insufficient input validation, allowing an application to send data that is not properly checked before use. This flaw can lead to corrupt kernel memory or cause the operating system to terminate unexpectedly. An exploitation path is possible if an application supplies malicious input, potentially triggering a kernel memory overwrite or a system crash, which results in loss of availability and possible integrity compromise on the affected device.
Affected Systems
Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS devices running any version older than the patched releases are vulnerable. The fix is delivered with iOS 26.5.2, iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6.
Risk and Exploitability
The CVSS score of 9.1 indicates a critical severity, while the EPSS score of < 1% suggests a low probability of exploitation in the wild. The flaw can be leveraged only by an application that runs on the device, implying a local exploitation scenario. The vulnerability is not listed in the CISA KEV catalog, and there is no evidence of remote or privilege‑escalation capabilities in the description.
OpenCVE Enrichment