Impact
An application can trigger an out-of-bounds write that bypasses bounds checking, resulting in unintended writes to kernel memory. The consequence is unexpected system termination or kernel memory corruption; the CVE does not specify that this leads to arbitrary code execution. Based on the description, the likely attack vector is an application that invokes the vulnerable code path, potentially a malicious or compromised app.
Affected Systems
Affected releases include iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27.
Risk and Exploitability
The CVSS score of 5.5 indicates a medium baseline risk. The EPSS score of <1% suggests a low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require a malicious or compromised application to invoke the vulnerable code; no public exploits are known, but kernel memory corruption could still destabilize the device.
OpenCVE Enrichment