Impact
An application may trigger unexpected system termination or write to kernel memory because of improper input sanitization. This flaw, classified as CWE‑20, threatens the integrity of the operating system and can cause denial of service.
Affected Systems
Apple iOS and iPadOS versions prior to 26.5.2, macOS Sequoia earlier than 15.7.8, macOS Sonoma earlier than 14.8.8, macOS Tahoe earlier than 26.5.2, tvOS earlier than 26.6, visionOS earlier than 26.6, and watchOS earlier than 26.6 are vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity issue, though the EPSS score of <1% shows a low likelihood of exploitation. Attackers are expected to use a malicious or compromised application that supplies crafted input to trigger the kernel memory write. Until the updates are applied, the risk remains significant.
OpenCVE Enrichment