Impact
A use‑after‑free flaw in Apple’s operating systems can allow a malicious application to use a freed memory reference, potentially causing unexpected system termination or writing data to kernel memory. The vulnerability is rooted in insufficient memory management and is identified as a classic use‑after‑free weakness. The impact includes system instability and the possibility of writing to privileged memory, which could elevate an attacker’s privileges if combined with additional exploits.
Affected Systems
Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS versions prior to 26.6 are susceptible. The flaw is fixed in iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6.
Risk and Exploitability
The CVSS score of 9.8 indicates very high severity. The EPSS score of < 1% suggests a very low but non‑zero probability of exploitation in the wild. Because the vulnerability is not listed in the CISA KEV catalog, there is no evidence of active exploitation, but its high severity and kernel‑level impact make it a high‑risk condition. A malicious application can trigger the use‑after‑free during its execution, providing an attacker with a pathway to corrupt kernel memory or cause a system crash. Without a KEV listing, defenders should treat this as a potentially active threat pending new evidence and apply the vendor patch promptly.
OpenCVE Enrichment