Impact
An out‑of‑bounds read can occur when an application accesses a memory region beyond a defined array boundary. The flaw was mitigated by adding improved bounds checking, but the presence of the vulnerability allows an application to cause the operating system to terminate abnormally, resulting in a denial‑of‑service condition.
Affected Systems
Affected Apple operating systems include iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6. Any device running a version earlier than these specified releases is potentially vulnerable.
Risk and Exploitability
The EPSS score is < 1%, indicating a very low but non‑zero exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the flaw permits any malicious application to trigger a crash, providing a straightforward denial‑of‑service attack vector. Since no specific access requirements are disclosed, it is inferred that the attack can be performed locally by applications granted the ability to run on the device.
OpenCVE Enrichment