Impact
A race condition in a core kernel component allows a local user to trigger an unexpected system termination or read kernel memory. The vulnerability is rooted in improper synchronization (CWE-362). Consequently, a local attacker or an authenticated user could cause application or system crashes and gain visibility of privileged information, which may aid in further exploitation. Based on the description, it is inferred that the defect requires local privilege and does not provide a remote attack vector.
Affected Systems
Apple iOS, iPadOS, macOS, tvOS, visionOS, and to 27 on each platform contain the race condition; iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27 include the additional validation that fixes the issue.
Risk and Exploitability
The vulnerability has a CVSS score of 8.1, but its EPSS score is less than 1 %, indicating a very low likelihood of exploitation under current threat conditions. It is not listed in the CISA KEV catalog. Risk is confined to individuals with local access, and the impact ranges from system instability to potential disclosure of kernel memory. While the flaw does not appear to support remote exploitation, a local attacker could indirectly leverage the situation for privilege escalation if kernel data is useful.
OpenCVE Enrichment