Impact
The vulnerability originates from improper memory handling in the Apple kernel, allowing a local attacker to trigger kernel memory corruption or unexpected system termination. A local compromise can lead to denial of service by forcing the system to shut down or potentially expose corrupted memory data.
Affected Systems
Apple iOS and iPadOS devices running versions earlier than 26.7, and macOS installations before macOS Golden Gate 27, macOS Sequoia 15.8, or macOS Tahoe 26.7, remain vulnerable. Security updates in iOS 26.7 and later, iPadOS 26.7 and later, macOS Golden Gate 27 and later, macOS Sequoia 15.8 and later, and macOS Tahoe 26.7 and later address the issue.
Risk and Exploitability
The flaw requires local access; a physical or local attacker can exploit it. The CVSS score of 8.4 indicates high severity, while the EPSS score of < 1 % indicates a very low likelihood of widespread attacks. The vulnerability is not listed in the CISA KEV catalog. Kernel memory corruption or system termination compromises availability and could serve as a foothold for further local exploitation. Understanding the risk is critical to prioritize patching and physical security.
OpenCVE Enrichment