Impact
The flaw is a race condition (CWE-362) in state management of Apple operating systems that can be triggered by a sandboxed application to create a timing window during which the kernel’s privilege level is improperly elevated. This vulnerability allows an attacker to execute arbitrary code with kernel privileges, compromising the confidentiality, integrity, and availability of the device if successfully exploited.
Affected Systems
Apple devices running iOS or iPadOS versions older than 26.7, iOS or iPadOS 26.x, macOS older than Golden Gate 27, Sequoia 15.8, Tahoe 26.7, tvOS, visionOS, and watchOS older than 27 are affected. The issue is fixed in iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, Sequoia 15.8, Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, and the EPSS score of <1% shows a very low expected exploitation probability. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploitation. Attackers would need to supply a malicious sandboxed application, so the risk is tied to installing apps from non‑trusted sources, potentially enabling widespread compromise if the flaw is exploited.
OpenCVE Enrichment