Impact
The vulnerability is a use‑after‑free flaw that enables a malicious application to cause the operating system to terminate unexpectedly. Exploiting this flaw can lead to a complete denial of service, disrupting user experience and potentially compromising system stability.
Affected Systems
Apple devices running iOS, iPadOS, macOS, tvOS, or watchOS are affected. The security fix is included in iOS 26.6 and iPadOS 26.6, macOS 26.6, tvOS 26.6, and watchOS 26.6. Devices with earlier OS releases remain vulnerable.
Risk and Exploitability
Exploitation requires an attacker to supply or manipulate a malicious app’s memory usage; the description does not specify network or elevation prerequisites. The EPSS score of <1% indicates a very low but nonzero likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread attacks have been observed. The high CVSS score of 9.8 reflects the severity of the denial‑of‑service impact. The likely attack vector is an application‑based attack delivered through the App Store or sideloaded software.
OpenCVE Enrichment