Impact
A timing race condition within the operating‑system core can allow a malicious application to trigger unexpected system termination or corrupt kernel memory. The flaw stems from improper synchronization, which may lead to loss of data, compromise of system integrity, and denial of service by forcing the device to reboot.
Affected Systems
Apple devices running iOS 26.7 or 27, iPadOS 26.7 or 27, macOS Golden Gate 27, Sequoia 15.8, and Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27 are affected. The vulnerability has been fixed in all subsequent OS releases.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of <1% suggests a very low probability of exploitation at this time. The flaw is not listed in CISA’s KEV catalog. Attackers would most likely trigger the race condition by installing a malicious or buggy application with elevated privileges; this inference is drawn from the description that an app may cause the failure. Because the vulnerability affects kernel memory, a successful exploit could lead to denial of service or potential privilege escalation if the attacker also gains code execution, though such escalation is not explicitly documented.
OpenCVE Enrichment