Impact
The vulnerability arises when an application can trigger unexpected system termination due to missing runtime checks in the operating system. Based on the description, it is inferred that the flaw allows a calling application to force a crash, which translates to a denial of service affecting device availability. The weakness aligns with the CWE-248 and CWE-400 designations for unexpected behavior and resource exhaustion, respectively.
Affected Systems
Apple's iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are affected. Versions prior to iOS 26.7 or 27, iPadOS 26.7 or 27, macOS Golden Gate 27 or earlier, macOS Tahoe 26.7 or earlier, and tvOS, visionOS, watchOS version 27 or earlier are vulnerable. The flaw is fixed in the listed releases of each operating system.
Risk and Exploitability
The CVSS score of 7.5 indicates a high‑impact denial of service, while the EPSS score of less than 1 % shows that public exploitation is unlikely at this time and the flaw is not cataloged in the CISA KEV list. The description does not specify a remote attack surface; therefore, it is inferred that the most plausible vector is local or application‑based, meaning that any third‑party application with execution privileges could exploit the flaw to crash the device.
OpenCVE Enrichment