Impact
A null pointer dereference in Apple iOS and iPadOS may allow an application to trigger an unexpected system termination, effectively causing a denial of service. This vulnerability is a classic example of CWE‑476 and directly compromises system availability for the affected device.
Affected Systems
The flaw affects Apple iOS and iPadOS running versions prior to 18.7.9 or 26.5. The security fix was delivered in iOS 18.7.9, iPadOS 18.7.9, iOS 26.5, and iPadOS 26.5 as announced by Apple.
Risk and Exploitability
The risk is limited to denial of service through application‑initiated crashes; there is no remote code execution or data disclosure. The CVSS score of 5.5 indicates moderate severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the installation or execution of a malicious or poorly written application that exploits the null pointer. Exploitation requires the victim to run the offending app, and therefore is confined to local device usage.
OpenCVE Enrichment