Impact
The vulnerability arises from a memory handling flaw that can lead to an unexpected system termination. Based on the CWE tags, it likely involves a buffer over‑read/overrun (CWE-125), a use‑after‑free (CWE-416), or an out‑of‑bounds write (CWE-787). It can be triggered by a locally running application, and an attacker with the ability to run a malicious or compromised application on the device can cause the affected device to crash, resulting in a denial of service for the user. No evidence indicates that the crash permits data loss or unauthorized disclosure; the primary impact is service interruption.
Affected Systems
Apple iOS versions 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 are affected. The flaw is tied to memory handling within the operating system, affecting all devices running these OS releases.
Risk and Exploitability
Because the description refers to a local, application‑level exploit. The EPSS score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The risk remains that any malicious app could disrupt device operation. The impact is limited to denial of service rather than data compromise, and the likelihood of exploitation is uncertain but could increase if the flaw is discovered publicly. The CVSS score of 5.5 indicates moderate severity.
OpenCVE Enrichment