Impact
A double free vulnerability was addressed by improving memory management. The issue allows an app to trigger unexpected system termination or corrupt kernel memory, potentially leading to arbitrary code execution or denial of service. The official description does not state the exact attack vector, but the nature of the flaw suggests it can be exploited when the offending code is executed with elevated privileges, such as within a system service or trusted application.
Affected Systems
Apple devices running iOS, iPadOS, macOS, tvOS, visionOS, or watchOS are affected. The vulnerability is fixed in iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, macOS Golden Gate 27, Sequoia 15.8, Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27.
Risk and Exploitability
The vulnerability is not listed in CISA KEV, but the effect of corrupting kernel memory indicates a high impact risk. The EPSS score is < 1%, indicating a very low likelihood of exploitation. Attackers with local or remote access to a vulnerable application could still achieve privilege escalation or system crash. High severity warrants prompt attention.
OpenCVE Enrichment