Impact
The vulnerability is a use‑after‑free that can cause a system crash when an application interacts with freed memory, a classic form of memory corruption consistent with CWE‑416. It does not provide code execution or data exfiltration, but it can disrupt the user experience by forcing an unexpected termination of the device or application.
Affected Systems
Apple iOS and iPadOS releases prior to 26.7 and 27, macOS releases older than Golden Gate 27, Sequoia 15.8, and Tahoe 26.7, as well as tvOS, visionOS, and watchOS versions earlier than 27. Any device running these operating systems on the listed platforms is potentially affected.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score is < 1%, indicating a very low likelihood of exploitation. The flaw requires a malicious or compromised application to trigger the use‑after‑free, making it a local or device‑wide scenario rather than a remote attack vector. It is not listed in CISA's KEV catalog, further indicating a minimal exploitation risk. The risk is limited to application crashes and denial of service until the device is updated to a patched release.
OpenCVE Enrichment