Impact
A reachable assertion within the operating system was triggered by malformed network input (CWE-617). The flaw stems from insufficient input validation, causing the system to hit an assertion, crash, and halt normal operation until a reboot. The issue was resolved by improving validation logic in subsequent OS releases.
Affected Systems
All Apple iOS and iPadOS releases older than 18.7.10 (including the 26.5 branch) are affected, as are macOS Tahoe 26.5, visionOS 26.5, and watchOS 26.5. Devices running these versions may crash when exposed to crafted packets that exploit the assertion failure.
Risk and Exploitability
The CVSS score of 6.5 denotes a medium‑high risk assessment. The EPSS score of <1 % indicates a very low probability of real‑world exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no known public exploits. An attacker in a privileged network position could send malicious packets to trigger the assertion, causing a denial of service that persists until the device reboots.
OpenCVE Enrichment