Impact
Apple has identified a race condition that can allow an application to trigger unexpected system termination. The resulting crash provides attackers with a denial of service vector, potentially disrupting active user sessions. The flaw does not enable code execution or privilege escalation; its effect is limited to system availability.
Affected Systems
Affected Apple platforms include iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27. All devices running these operating systems without the corresponding updates are vulnerable.
Risk and Exploitability
The EPSS score of < 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, meaning no known active campaigns. The race condition can lead to device crashes, as described. Based on the description, it is inferred that the attacker would need to deliver or run a malicious application locally to trigger the fault. Updating to any of the patched versions is the only known method to mitigate the risk.
OpenCVE Enrichment