Impact
The vulnerability is caused by insufficient input sanitization, which allows untrusted data to be used for writes to kernel memory. An attacker targeting an application could trigger the flaw, leading to unexpected system termination or corruption of kernel memory.
Affected Systems
Apple iOS, iPadOS, and macOS devices running versions prior to iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2 are affected. The issue is fixed in those release versions, so any device not updated to these builds remains vulnerable.
Risk and Exploitability
The EPSS score is < 1% and the CVSS score of 7.8 indicates a high‑severity flaw. The likely attack vector is through a malicious or compromised application that supplies crafted input, which could trigger the kernel write. The risk assessment considers the possibility of unexpected shutdowns or kernel corruption. Until devices are updated, any application that can be controlled by an attacker remains a potential exploitation path.
OpenCVE Enrichment