Impact
An out-of-bounds read vulnerability was discovered in Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS that can allow a local application to trigger unexpected device termination or read kernel memory, exposing privileged information. The flaw is due to insufficient input validation and is classified as CWE-125. As a result, unauthorized access to kernel data structures may occur, potentially compromising system confidentiality and stability.
Affected Systems
Apple iOS versions prior to 26.6.1, iPadOS prior to 26.6.1, macOS Sequoia versions prior to 15.8 and macOS Tahoe prior to 26.6.2, tvOS prior to 27, visionOS prior to 27, and watchOS prior to 27 are vulnerable. All earlier releases of these operating systems are affected.
Risk and Exploitability
The CVSS score of 6.6 indicates moderate severity, while the EPSS score of less than 1 % reflects a very low likelihood of exploitation. The vulnerability is not listed in KEV. Based on the description, it is inferred that a malicious local application could trigger the out-of-bounds read by supplying specially crafted input, thus the attack surface appears to be the application level and the impact is confined to the device where the app runs.
OpenCVE Enrichment