Impact
The vulnerability is a write-after-buffer boundary error that allows an application to overwrite adjacent memory, including kernel data structures. This can lead to unexpected system termination or the corruption of critical data within the operating system. The weakness is classified as CWE-120 and carries the potential for severe stability and integrity impact.
Affected Systems
Devices running Apple iOS, iPadOS, macOS, tvOS, visionOS, or watchOS with a release prior to 26.6 are affected. The flaw is remedied in iOS 26.6, iPadOS 26.6, macOS 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity risk, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, implying no known public exploitation. Based on the description, it is inferred that the attack vector would likely involve a malicious or compromised local application that can trigger the buffer overflow, requiring the attacker to have a foothold on the device to exploit the vulnerability. Successful exploitation could corrupt kernel memory, potentially allowing elevated privileges or complete system takeover.
OpenCVE Enrichment