Impact
The vulnerability is a use‑after‑free issue that was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, and watchOS 27. A remote attacker may be able to cause unexpected system termination.
Affected Systems
All Apple iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS devices running any version prior to the releases mentioned above are vulnerable. Devices updated to iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, or watchOS 27 are not affected.
Risk and Exploitability
The CVSS score is 7.5 and the EPSS score is < 1%, while the vulnerability is not listed in the CISA KEV catalog. The description indicates that a remote attacker may cause the system to terminate, suggesting a remote attack vector, though the precise remote interface is not detailed by Apple. The lack of exploitation statistics means the likelihood is uncertain, but the impact is definite if the flaw is successfully triggered.
OpenCVE Enrichment