Impact
The vulnerability is a memory handling flaw in Apple operating systems that can be triggered by an application. It is classified as a buffer overflow (CWE-119). An attacker can cause corruption of kernel memory or trigger an unexpected system termination, compromising the integrity and availability of the affected device. No obvious impact on confidentiality is noted, but the ability to overwrite kernel structures could lead to privilege escalation or denial of service.
Affected Systems
Affected are Apple’s iOS and iPadOS systems running any version prior to 26.6.1, and macOS Tahoe releases earlier than 26.6.2. These operating system versions are present on iPhones, iPads, and Mac computers that have not applied the latest security update from Apple. Devices with the patch are not susceptible.
Risk and Exploitability
The CVSS score is 6.5, indicating medium severity. The EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not yet listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is via an application that a user installs or runs. No public exploit is currently available, and the flaw requires elevated privileges or code execution in an app to trigger the memory corruption.
OpenCVE Enrichment