Impact
A null pointer dereference occurs when Apple devices process web content. The flaw allows an attacker to trigger the dereference, forcing the operating system to terminate and restart. As a result, the device experiences a denial‑of‑service that disrupts normal operation. This weakness is classified as CWE‑476.
Affected Systems
Multiple Apple platforms are affected. The defect is present in iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, and watchOS 27. All devices running these releases or earlier are susceptible until a later update is installed.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of <1% suggests a low probability of exploitation. The vulnerability can be triggered simply by processing arbitrary web content, so any device that renders such content could be targeted. Although the issue is not listed in CISA’s KEV catalog, the denial‑of‑service impact remains significant for end‑users and services that rely on continuous device availability.
OpenCVE Enrichment