Impact
The vulnerability involves improper memory handling in Apple operating systems, allowing an attacker on the local network to trigger a fault that can cause denial‑of‑service. The issue was addressed with improved memory handling and is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.8, macOS Sonoma 14.8.7, macOS Tahoe 26.5, and tvOS 26.5. The flaw can lead to resource exhaustion or system instability requiring a restart. It is identified as CWE‑400.
Affected Systems
The flaw impacts iOS and iPadOS, macOS, and tvOS. On iOS and iPadOS the affected versions are those prior to 18.7.9 and 26.5, on macOS the Sequoia 15.7.8, Sonoma 14.8.7 and Tahoe 26.5 families, and on tvOS versions before 26.5. Devices running newer releases incorporate the patch that corrects the memory handling issue.
Risk and Exploitability
The CVSS score is 6.2, indicating moderate severity. The EPSS score is <1%, indicating a low but nonzero exploitation probability, and the vulnerability is not listed in CISA’s KEV catalogue, suggesting that public exploitation has not been recorded. However, because the attack vector is local network activity, a threat actor positioned on the same network as the device can potentially induce the denial‑of‑service. The absence of a publicly available exploit does not reduce the risk to organizations that host exposed Apple devices.
OpenCVE Enrichment