Impact
An out-of-bounds write issue was identified in several Apple operating systems. The vulnerability allows a remote attacker to send crafted input that can corrupt heap memory or cause application termination. It is fixed in iOS 18.7.10, iPadOS 18.7.10, iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, and visionOS 26.6, meaning earlier versions remain vulnerable. The main impact is service disruption due to application crashes or memory corruption.
Affected Systems
Apple’s mobile and desktop operating systems are affected. Devices running iOS versions earlier than 18.7.10, iOS versions earlier than 26.6, iPadOS versions earlier than 18.7.10, iPadOS versions earlier than 26.6, macOS Sequoia versions earlier than 15.7.8, macOS Tahoe versions earlier than 26.6, tvOS versions earlier than 26.6, and visionOS versions earlier than 26.6 are vulnerable.
Risk and Exploitability
The CVSS score of 9.8 indicates a high severity vulnerability, and the EPSS score of less than 1 % suggests a low but nonzero likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, implying no known public exploitation. A remote attacker can trigger the flaw by delivering malicious input from outside the device, likely causing application termination or memory corruption.
OpenCVE Enrichment