Impact
The vulnerability is a double‑free bug that was mitigated by enhancing memory management. Processing maliciously crafted web content may still trigger the double free, leading to an unexpected process crash. The crash causes denial of service but does not allow the attacker to execute arbitrary code or gain elevated privileges.
Affected Systems
Apple devices running iOS, iPadOS, macOS, tvOS, visionOS, or watchOS versions older than the releases listed in the advisory remain vulnerable. The patched releases are iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% shows a low likelihood of exploitation at this time, and the issue is not listed in the CISA KEV catalog. Remote exploitation would involve delivering malicious web content that triggers the double free, causing the affected process to crash. The flaw does not provide code execution or privilege escalation capabilities.
OpenCVE Enrichment