Impact
The vulnerability originates from a memory handling flaw in Apple’s operating systems that can be triggered by maliciously crafted web content. When the flaw is exercised, an unexpected process crash occurs, leading to a denial of service on the affected device. The flaw does not grant privilege escalation or remote code execution; its effect is limited to availability loss.
Affected Systems
The vulnerability affects Apple iOS, iPadOS, macOS (Sequoia 15.7.8, Sonoma 14.8.8, Tahoe 26.5.2), tvOS 26.6, visionOS 26.6, and watchOS 26.6. Versions prior to these patches are vulnerable.
Risk and Exploitability
The CVSS score reported is 6.5, which denotes a medium severity. The EPSS score is reported as < 1%, indicating a very low exploitation probability, and the vulnerability is not listed in CISA KEV. The flaw can be triggered by loading malicious web content through a browser or any web-enabled application, which is a likely attack vector. Because the impact is only an application crash and no control‑flow takeover is possible, the risk is moderate and primarily an availability threat for single devices, with exploitation being relatively straightforward in a user‑directed attack.
OpenCVE Enrichment