Impact
A race condition was identified in Apple operating systems that may allow a sandboxed application to execute arbitrary code with kernel privileges. The security advisory notes that the issue has been mitigated by improving state management, but does not provide further detail on the specific execution path. The potential impact is that an attacker could gain kernel‑level access, compromising confidentiality, integrity, and availability of the device.
Affected Systems
Apple iOS 26.7 through 27, iPadOS 26.7 through 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27 are all affected. The issue has been addressed in these releases by enhancing state handling to prevent the race condition.
Risk and Exploitability
Because the flaw can enable kernel‑level code execution, the potential impact is severe. The EPSS score is unavailable and the vulnerability has not been listed in the CISA KEV catalog, indicating limited evidence of exploitation in the wild. Nonetheless, the likely attack vector involves a malicious sandboxed application; any user who installs such an app from outside the trusted App Store could be at risk.
OpenCVE Enrichment