Impact
An application may trigger unexpected system termination or write kernel memory due to improper input sanitization. This flaw, classified as CWE‑20, threatens the integrity of the operating system and, based on the description, can lead to denial of service.
Affected Systems
Apple iOS and iPadOS versions prior to 18.7.10 and 26.5.2, macOS Sequoia earlier than 15.7.8, macOS Sonoma earlier than 14.8.8, macOS Tahoe earlier than 26.5.2, tvOS earlier than 26.6, visionOS earlier than 26.6, and watchOS earlier than 26.6 are vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity issue, though the EPSS score of <1% shows a low likelihood of exploitation. Attackers are expected to use a malicious or compromised application that supplies crafted input to trigger the kernel memory write. Until the updates are applied, the risk remains significant.
OpenCVE Enrichment