Description
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
Published: 2026-07-27
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A race condition exists in Apple operating system state handling that can be triggered by an application, leading to unexpected system termination. The flaw is catalogued as CWE-362. The vulnerability does not provide privilege escalation or data exposure; its impact is limited to denial of service.

Affected Systems

Apple iOS, iPadOS, macOS Tahoe, tvOS, and watchOS running any version before iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, or watchOS 26.6 are affected. The entry does not list specific older releases.

Risk and Exploitability

The CVSS base score of 9.8 indicates severe impact. The EPSS score of less than 1% and absence from the CISA KEV catalog suggest low current exploitation likelihood. Exploitation would require an application to trigger the race condition; the description does not specify the privilege level required, so the likely attack vector is local or application‑level, which is inferred from the mention of an app. The absence of detailed exploitation steps or required timing makes the likelihood of a successful attack uncertain.

Generated by OpenCVE AI on August 4, 2026 at 23:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all affected Apple devices to iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, or watchOS 26.6 to receive the vendor‑supplied patch.
  • If an immediate upgrade is not feasible, identify and remove any applications that may trigger the race condition, especially during critical operations.
  • Implement continuous monitoring for unexpected system terminations and set alerts to detect potential exploitation early.

Generated by OpenCVE AI on August 4, 2026 at 23:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Race Condition Causing Unexpected System Termination in Apple Operating Systems

Tue, 04 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title Race Condition Allowing Unexpected System Termination in Apple Operating Systems
Weaknesses CWE-410

Thu, 30 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Race Condition Allowing Unexpected System Termination in Apple Operating Systems
Weaknesses CWE-410

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T15:49:11.712Z

Reserved: 2026-07-20T18:09:35.084Z

Link: CVE-2026-64720

cve-icon Vulnrichment

Updated: 2026-07-28T15:48:54.932Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:10.950

Modified: 2026-07-28T19:53:51.337

Link: CVE-2026-64720

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T23:45:02Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')