Impact
The issue is improper memory handling in several Apple operating systems, fixed in iOS 18.7.10, iPadOS 18.7.10, iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6. An attacker on the local network may be able to cause a denial-of-service by triggering improper memory accesses, leading to system crashes and availability disruption. The weakness aligns with a resource exhaustion scenario (CWE‑400).
Affected Systems
Affected Apple products include iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. It is inferred that versions before iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6 are susceptible. The security update in these releases addresses the defect.
Risk and Exploitability
The EPSS score is less than 1 %, indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, signifying no known mass‑targeted attacks. The CVSS score of 5.5 reflects a moderate impact when exploiting the flaw. An attacker must be on the local network and capable of sending crafted traffic to trigger the improper memory handling, which can lead to a denial‑of‑service. Given the low exploitation likelihood, the risk remains moderate but remediation is still advisable.
OpenCVE Enrichment