Impact
A race condition was discovered in the filesystem integrity checks of Apple iOS and iPadOS. The flaw allows an application to create a timing gap between the check and the execution of a privileged file‑system operation, enabling it to overwrite or replace protected files. The impact is a potential compromise of system integrity or the execution of malicious code with elevated privileges, aligning with CWE‑362.
Affected Systems
Apple iOS and iPadOS devices running versions before iOS 18.7.10 or iPadOS 18.7.10 and before iOS 26.6 or iPadOS 26.6 are affected. The affected versions are inferred from the fixed‑version information included in the advisory; the CVE description does not list them explicitly. Devices running iOS 18.7.10/iPadOS 18.7.10 or later, including iOS 26.6/iPadOS 26.6, contain the race‑condition fix and are no longer vulnerable.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate severity; the EPSS score of less than 1 % indicates a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The flaw is likely exploitable only with local or application‑level access, as an attacker must run code on the device to create the race condition. While the risk remains limited to devices on older firmware, any exposed system file could be modified, potentially leading to privilege escalation or persistence.
OpenCVE Enrichment