Impact
A fault in Apple’s operating systems introduces an out‑of‑bounds access due to missing bounds checking, enabling a malicious app to read or write beyond allocated memory. The flaw occurs in kernel code, so the attacker could cause the system to terminate unexpectedly or corrupt critical kernel structures, resulting in denial of service or kernel memory corruption.
Affected Systems
The vulnerability affects all Apple operating systems including iOS, iPadOS, macOS Golden Gate, tvOS, visionOS and watchOS on devices running a version earlier than 27. Apple has released version 27 of each of those systems with the fix applied.
Risk and Exploitability
The kernel‑level nature of the bug indicates a high severity. A malicious application may be able to trigger unexpected system termination or corrupt kernel memory. The EPSS score of < 1% suggests a very low exploitation probability. The issue is not listed in the CISA KEV catalog, but the potential for system crash or kernel corruption warrants treating it as a high‑risk vulnerability.
OpenCVE Enrichment