Impact
An out‑of‑bounds access flaw was found due to insufficient bounds checking. The vulnerability can allow an application to trigger unexpected system termination or corrupt kernel memory. The weakness is categorized as CWE‑125 and CWE‑787, which may enable arbitrary code execution or denial of service if the kernel is compromised.
Affected Systems
Apple devices running iOS, iPadOS, macOS, tvOS, visionOS, or watchOS are impacted. The fix is included in iOS 26.6.1 and iPadOS 26.6.1; macOS Sequoia 15.8 and macOS Tahoe 26.6.2; tvOS 27; visionOS 27; and watchOS 27. All earlier releases remain vulnerable.
Risk and Exploitability
The CVSS score of 7.1 reflects high severity, while an EPSS score of less than 1 percent indicates a very low likelihood of widespread exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, exploitation appears to require a local application running on the device; no remote exploitation path has been documented. Organizations should therefore consider the flaw a high‑severity kernel flaw that could permit privilege escalation if an app can trigger the error.
OpenCVE Enrichment