Impact
A race condition in the operating system’s core logic allows a local user to trigger an unexpected system termination and, through a timing discrepancy, read kernel memory. The flaw is not exploitable remotely and requires the attacker to have local login or physical access to the device. The resulting impact ranges from application/system crashes to potential visibility of sensitive kernel data, which could aid in further privilege escalation or forensic analysis.
Affected Systems
Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are affected. Versions earlier than 27 on each platform lack the fix; iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27 contain the additional validation that resolves the race condition.
Risk and Exploitability
The vulnerability has no publicly available remote exploitation vector, no EPSS data, and is not listed in the CISA KEV catalog. The risk level is contingent on a local attacker’s ability to trigger the race condition, which would lead to system instability or kernel memory disclosure. The absence of remote attack pathways reduces the immediate threat, but the potential for local privilege escalation remains if memory content can be leveraged.
OpenCVE Enrichment