Impact
A use‑after‑free vulnerability (CWE-416) was identified in Apple operating systems that allows an application to trigger unexpected system termination, effectively denying users the ability to use their devices.
Affected Systems
Apple iOS 26.6 27; iPadOS 26.6, 26.7, and 27; macOS Golden Gate 27, Sequoia 15.8, Tahoe 26.6, and 26.7; tvOS 26.6, 27; visionOS 26.6OS 26.6, 27 are affected. Any application that can be executed on the device may trigger the use‑after‑free condition.
Risk and Exploitability
The EPSS score is <1%, indicating a very low but nonzero likelihood of exploitation. This vulnerability is not listed in the KEV catalog, as the bug is triggered by. Because the bug resides in core system libraries, exploitation requires a specially crafted app but does not need privileged access. Despite the low EPSS, the potential for a denial‑of-service condition warrants prompt remediation.
OpenCVE Enrichment