Impact
The vulnerability is a use‑after‑free flaw that Apple addressed through improved memory management. The issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6 and watchOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory, potentially leading to crashes or compromised system integrity.
Affected Systems
Devices running versions of Apple iOS, iPadOS, macOS, tvOS, visionOS, or watchOS older than the fixed releases are vulnerable. This includes iPhones, iPads, Macs, Apple TV devices, visionOS devices, and Apple Watches that are not on iOS 18.7.10 or 26.6, iPadOS 18.7.10 or 26.6, macOS Sequoia 15.7.8 or Sonoma 14.8.8 or Tahoe 26.6, tvOS 26.6, visionOS 26.6, or watchOS 26.6.
Risk and Exploitability
The EPSS score indicates very low but non‑zero exploitation probability. The CVSS score of 9.8 signals a critical severity, reflecting the potential for system termination and kernel memory corruption. The vulnerability remains not listed in the CISA KEV catalog, so no confirmed exploits are known. The attack vector is not explicitly stated, but based on typical use‑after‑free flaws, it is inferred that the attacker would need to interact with or compromise an application, leading to a local or application‑compromise scenario. Until a patch is applied, administrators should treat this as a significant risk.
OpenCVE Enrichment