Impact
A use‑after‑free flaw was identified in several Apple operating systems that can be triggered when an application accesses memory that has been freed. The result is that the operating system terminates unexpectedly, leading to a denial‑of‑service condition. No evidence of arbitrary code execution or privilege escalation exists in the description, so the primary impact is loss of availability rather than confidentiality or integrity.
Affected Systems
Apple iOS, iPadOS, macOS, of the Apple operating system. The vulnerability is resolved in iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6 and watchOS 26.6.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while the EPSS score of <1% reflects a very low likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack vector is local, requiring the presence of a malicious or specially crafted application on the device. As a result, confidentiality and integrity risks are low; the primary risk remains a loss of availability through unexpected system termination.
OpenCVE Enrichment