Impact
The vulnerability is a use‑after‑free flaw that was fixed by improving memory management. An attacker that can reach the vulnerable code may trigger an unexpected system termination, effectively causing a denial of service. The weakness is a classic use‑after‑free, making the application or operating system unstable once the memory is accessed after its lifetime has ended.
Affected Systems
Any Apple iOS or iPadOS device with a version earlier than 26.6.1, and any macOS Tahoe device with a version earlier than 26.6.2, is affected. Devices that have been updated to iOS 26.6.1, iPadOS 26.6.1, or macOS Tahoe 26.6.2 are not vulnerable.
Risk and Exploitability
The CVSS score is 7.5 and the EPSS score is < 1%, while the vulnerability is not listed in the CISA KEV catalog. The description indicates that a remote attacker can cause the system to terminate, suggesting a remote attack vector, though the precise remote interface is not detailed by Apple. The lack of exploitation statistics means the likelihood is uncertain, but the impact is definite if the flaw is successfully triggered.
OpenCVE Enrichment