Impact
This vulnerability arises from insufficient handling of memory in the kernel, allowing a remote user to trigger memory corruption that can lead to unexpected system termination. The primary impact is denial of service through a kernel crash or memory corruption, which compromises availability. The weakness is a classic buffer overflow or use‑after‑free type error (CWE‑119).
Affected Systems
Affected systems include all Apple macOS, iOS, and iPadOS releases prior to the following patches: macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, iOS 18.7.10, and iPadOS 18.7.10. Any device running versions older than these is potentially vulnerable. The issue was identified by Apple and resolved by updating the kernel memory manager, indicating the flaw resides in the operating system kernel.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in CISA KEV, suggesting no known exploitation yet. The CVSS score of 9.8 indicates a critical severity, with a considerable impact on confidentiality, integrity, and availability due to the kernel memory corruption. The likely attack vector is remote; a malicious user would need to exploit a remote service that interacts with kernel memory, as described by Apple, to trigger the fault. The low EPSS means the probability of real-world exploitation appears currently low, but the high severity warrants immediate patching.
OpenCVE Enrichment