Impact
A race condition in macOS state handling allows an application to trigger an unexpected system termination. The flaw does not provide remote code execution or data disclosure. Its primary impact is a denial‑of‑service by crashing the operating system, resulting in loss of availability.
Affected Systems
Apple macOS is affected. Users running any release earlier than macOS Golden Gate 27 or macOS Tahoe 26.7 remain vulnerable. The fix is incorporated in those two releases and in subsequent updates.
Risk and Exploitability
The CVSS score of 5.5 indicates medium severity. The EPSS score is below 1%, showing a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog and no active exploits have been reported. The likely attack vector is local, requiring an application to trigger the race condition, typically by running with elevated privileges.
OpenCVE Enrichment