Impact
An out‑of‑bounds read exists in Apple iOS, iPadOS, and macOS that can be triggered by a locally running or malicious application. The flaw allows the application to read data beyond the intended buffer, exposing kernel memory contents and potentially causing the operating system to terminate unexpectedly.
Affected Systems
Apple iOS version 26.6.1, iPadOS version 26.6.1, and macOS Tahoe version 26.6.2 are affected; all earlier releases are vulnerable and no other versions or products are listed.
Risk and Exploitability
The CVSS score of 6.6 indicates moderate severity, and the EPSS score of less than 1 % shows a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a local malicious application to provide specially crafted input; therefore the attack vector is application‑level and the impact is confined to the affected device.
OpenCVE Enrichment