Impact
A null pointer dereference bug was detected in the rendering of web content on Apple devices. When untrusted content is processed, the system attempts to dereference a null pointer, causing the operating system to terminate abruptly and creating a denial‑of‑service condition. This weakness directly grants an attacker the ability to disrupt device functionality by sending crafted web pages or URLs the targeted device. The underlying vulnerability is a classic null pointer dereference, classified as CWE‑476.
Affected Systems
The flaw affects multiple Apple platforms. Software versions that contain the defect include iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, and watchOS 27. All devices running these or earlier releases are susceptible until a later update is installed.
Risk and Exploitability
The CVSS score is not publicly available, and EPSS data is not reported, so an exact quantitative risk is not provided. However, because the issue leads to a full system restart and it can be triggered by any web content, a high likelihood exists for exploitation in environments where unknown or untrusted content is rendered. The vulnerability is not listed in CISA's KEV catalog, which suggests no known active exploitation. Still, the attack vector—processing arbitrary web material—remains possible and the denial‑of‑service impact is severe for end‑users and services that rely on continuous device availability.
OpenCVE Enrichment