Impact
An attacker in physical proximity to an Apple device can trigger a memory corruption flaw that allows corrupting process memory. This flaw aligns with CWE-119 and may lead to application crashes, instability, or unintended behavior. The description does not indicate that arbitrary code execution is possible, but compromising memory integrity can expose the device to further attacks if the corruption is leveraged to influence execution flow.
Affected Systems
Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS devices that are running any software version prior to 26.6 are vulnerable, as the issue is fixed only in the 26.6 releases of each operating system.
Risk and Exploitability
The CVSS score of 9.8 indicates a high severity vulnerability, yet the EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting a low expected exploitation probability under normal conditions. The attack vector requires physical proximity, so an attacker must be near the device to trigger the memory corruption. No publicly documented exploit is available; however, high severity memory corruption flaws are generally considered high risk due to their potential to destabilize applications and enable further attacks.
OpenCVE Enrichment