Impact
The vulnerability consists of an out‑of‑bounds read in which code may access memory beyond an array’s bounds. Apple addressed this flaw with improved bounds checking in the released updates listed below. Before those patches, an application could trigger a crash that terminates the operating system, causing a denial‑of‑service.
Affected Systems
Affected Apple operating systems include iOS 18.7.10, iOS 26.6, iPadOS 18.7.10, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6. Any device running an earlier version is potentially vulnerable.
Risk and Exploitability
The EPSS score is < 1 %, indicating a very low but non‑zero exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. The flaw permits any malicious application to trigger a crash, providing a straightforward denial‑of‑service attack vector. Since no specific access requirements are disclosed, it is inferred that the attack can be performed locally by applications granted the ability to run on the device.
OpenCVE Enrichment