Impact
A type confusion flaw allowing an application to cause an unexpected system termination was identified in Apple operating systems. The vulnerability results from an object being misidentified as another type, leading to unsafe handling and a crash of the operating system. The crash stops the system from operating normally and can cause loss of device functionality.
Affected Systems
The flaw affects Apple’s mobile and desktop operating systems: iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27. Any device running one of these affected versions is susceptible to the crash triggered by a malicious application.
Risk and Exploitability
The EPSS score of less than 1% indicates a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog and no public exploitation is known. The CVSS score of 5.5 indicates moderate severity. Based on the description, it is inferred that the attack vector is local, with the flaw exploitable by a malicious application running on the device. Once exploited, the vulnerability results in a denial of service by terminating the operating system and may expose the device to additional instability if the crash occurs during critical operations.
OpenCVE Enrichment