Impact
The vulnerability is a kernel memory handling flaw on several Apple operating systems, classified as a buffer overflow (CWE-119). It can be triggered by an application, allowing potential corruption of kernel memory or unexpected system termination. The issue was addressed with improved memory handling and is fixed in iOS 26.6.1, iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, and watchOS 27. Although the description does not explicitly mention confidentiality impact, corrupting kernel structures could lead to privilege escalation or denial of service.
Affected Systems
Affected are Apple’s iOS and iPadOS systems running any version prior to 26.6.1, macOS Sequoia releases before 15.8, macOS Tahoe releases before 26.6.2, and the corresponding tvOS, visionOS, and watchOS versions earlier than 27. These operating system versions are present on iPhones, iPads, and Mac computers that have not applied the latest security fixes.
Risk and Exploitability
The CV medium severity. The EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not yet listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is via an application that a user installs or runs. No public exploit.
OpenCVE Enrichment