Impact
A race condition affecting state handling across Apple’s operating systems—iOS, iPadOS, macOS, tvOS, and watchOS—can be leveraged by a malicious or buggy application to cause unexpected system termination. The flaw existed in earlier releases and was fixed in iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, and watchOS 26.6. If an app exploits the race condition, the operating system may crash, disrupting user data and availability. This weakness aligns with CWE-362.
Affected Systems
Apple iOS and iPadOS devices running versions older than 26.5.2, macOS Tahoe older than 26.5.2, tvOS older than 26.6, and watchOS older than 26.6 are impacted. These systems contain the race condition flaw, which is addressed in the newer releases. No additional sub‑products are listed.
Risk and Exploitability
The CVE entry carries a CVSS score of 4.7, while the EPSS score indicates an exploitation probability of less than 1%, reflecting a very low likelihood. The vulnerability is not listed in CISA’s KEV catalog. Because the weakness involves application‑initiated race conditions, the likely attack vector is confined to applications running with sufficient privileges; no further exploit conditions or remote vectors are described, so the risk is considered limited to software containing the race condition flaw until a patch is applied.
OpenCVE Enrichment