Impact
The vulnerability is a use‑after‑free flaw that occurs when an application frees a memory resource and later accesses that same region. The improper memory access can destabilize normal operation, leading an operating system to terminate unexpectedly. The official description states that an app may be able to cause such termination, indicating a denial‑of‑service impact but no indication of code execution or data theft. The defect is corrected in iOS 27 and iPadOS 27, so devices upgraded to those releases are no longer vulnerable.
Affected Systems
Apple iOS and iPadOS devices running any version prior to 27 are affected. The defect is corrected in iOS 27 and iPadOS 27, so devices upgraded to those releases are no longer vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity focused on system availability. The EPSS score of less than 1% suggests a low likelihood of exploitation. The issue is a Use After Free (CWE-416) that can be triggered by an application’s memory misuse. The vulnerability does not provide privilege escalation or remote code execution; it only causes a denial of service. No publicly documented exploits exist because the vulnerability is not listed in CISA KEV. The attack vector appears to be local, requiring a malicious or compromised application to trigger the use‑after‑free.
OpenCVE Enrichment