Impact
An out-of-bounds write in Apple operating systems was resolved with enhanced bounds checking. The issue allowed an application to write outside the intended buffer, potentially overwriting kernel memory and causing the system to terminate unexpectedly. This type of memory corruption could enable privilege escalation or arbitrary code execution, impacting confidentiality, integrity, and availability of the device.
Affected Systems
Affected releases include iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, Sequoia 15.8, Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27.
Risk and Exploitability
The vulnerability can be leveraged by any app that runs with sufficient privileges to trigger the write. Without a publicly available exploit, the exact exploitation path is unclear, but the potential for kernel memory alteration is high. No exploit has been cataloged in CISA KEV, and no EPSS score is available, which leaves the real-world exploitation likelihood uncertain; nevertheless, the high potential impact warrants prompt remediation.
OpenCVE Enrichment