Impact
A use‑after‑free flaw in Apple’s memory‑management code can cause an app to read or write memory that has already been freed. This flaw is able to trigger unexpected system termination, effectively resulting in a denial of service when the vulnerable kernel or system component attempts to access the corrupted memory. The weakness corresponds to CWE‑416, the classic use‑after‑free defect.
Affected Systems
Apple iOS, iPadOS, macOS, and visionOS releases prior to the following fixed versions are affected: iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, and visionOS 27. All earlier builds remain vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity with an impact mainly limited to service disruption. The EPSS score of less than 1 % shows that exploitation is unlikely and no public exploits are known, which is consistent with its absence from the CISA KEV catalog. The attack vector is not explicitly detailed in the advisory; it is inferred that an attacker would need local or application‑delivery privileges to install a malicious app that abuses the use‑after‑free, making remote exploitation outside of a compromised device improbable.
OpenCVE Enrichment