Impact
A race condition in the state handling code of Apple operating systems can cause unexpected system termination or corruption of kernel memory. The flaw allows concurrent state changes to be improperly serialized, giving an application the ability to trigger overlapping operations that leave the kernel in an inconsistent state, potentially compromising system stability and integrity.
Affected Systems
Apple devices running iOS, iPadOS, macOS, tvOS, visionOS, or watchOS prior to the patch releases that include iOS 18.7.10, iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, or watchOS 26.6. All earlier versions are vulnerable.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low current likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. Exploitation would likely require a locally installed or compromised application that can trigger the race condition through coordinated state changes; thus, the attack vector appears to be local or bounded to trusted code execution.
OpenCVE Enrichment