Impact
The vulnerability arises from a flaw in the operating system’s memory handling routines that can be exploited by a malicious application. By triggering unexpected system termination or corrupting kernel memory, an attacker can alter privileged data structures and compromise kernel integrity. This weakness is a classic buffer overflow, identified as CWE-119, leading to a loss of system availability and potential loss of integrity, as corrupted kernel memory can enable unauthorized privilege escalation or cause system crashes.
Affected Systems
Apple iOS, iPadOS, macOS Sequoia, macOS Tahoe, and visionOS releases prior to iOS 18.7.10, iPadOS 18.7.10, iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, and visionOS 26.6 are affected. Devices running a version older than these patches are vulnerable until updated.
Risk and Exploitability
The issue is exploitable by any application capable of running on the device, and based on the description, it is inferred that the attack vector is local via any application. The CVSS score of 7.8 indicates moderate to high severity, and the EPSS score is < 1%, pointing to a very low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The potential impact is a system crash or compromise of privileged data, resulting in loss of availability and integrity. Attacks would require the malicious app to be installed or executed on the device, which is likely for end‑users, making the risk significant until mitigated by patching.
OpenCVE Enrichment