Impact
The vulnerability is a use‑after‑free that allows an application to access memory that has already been released. When such an access occurs, the operating system or a critical subsystem can crash, resulting in an unexpected termination of the device. This flaw does not give attackers direct code execution, but the crash provides a reliable denial of service channel.
Affected Systems
Apple’s major operating systems are affected: iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The flaw exists in all releases older than iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6.
Risk and Exploitability
The CVSS score of 9.8 reflects the high impact of the crash, while the EPSS score of less than 1% indicates a currently low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, and there are no publicly documented exploits. Based on the description, it is inferred that the most probable attack vector would involve a crafted application that triggers the use‑after‑free, which can be achieved by installing or running malicious software on the device. Due to the severity of the potential denial of service, the flaw deserves immediate attention for any unpatched system.
OpenCVE Enrichment