Impact
A race condition that can be triggered by an application was identified across Apple’s operating systems including iOS, iPadOS, macOS (Tahoe), tvOS, and watchOS. Apple addressed this flaw by improving state handling, with fixes available in iOS 26.5.2, iOS 26.7, iPadOS 26.5.2, iPadOS 26.7, macOS Tahoe 26.5.2, macOS Tahoe 26.7, tvOS 26.6, and watchOS 26.6. Before the patches, the race condition could lead to unexpected system termination, as an app might trigger it.
Affected Systems
Apple iOS, iPadOS, macOS, tvOS, and watchOS versions prior to the releases that fix the issue—iOS 26.5.2 and 26.7, iPadOS 26.5.2 and 26.7, macOS Tahoe 26.5.2 and 26.7, tvOS 26.6, and watchOS 26.6—are vulnerable.
Risk and Exploitability
The CVE entry carries a CVSS score of 4.7, while the EPSS score indicates an exploitation probability of less than 1%, reflecting a very low likelihood. The vulnerability is not listed in CISA’s KEV catalog. Because the weakness involves application‑initiated race conditions, the likely attack vector is confined to applications running with sufficient privileges; no further exploit conditions or remote vectors are described, so the risk is considered limited to software containing the race condition flaw until a patch is applied.
OpenCVE Enrichment