Impact
An app that triggers a type confusion flaw can cause improper memory handling, leading to unexpected system termination. The resulting denial of service disrupts user workflows and threatens system stability. No evidence of code execution or data exfiltration is supplied, so the vulnerability is confined to availability.
Affected Systems
Apple iOS and iPadOS versions prior to 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27 are vulnerable. All earlier releases of these operating systems are at risk if applications that can invoke the affected APIs are installed.
Risk and Exploitability
The EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is 5.5, indicating a moderate severity. The likely attack vector is local application execution, inferred from the necessity of running a malicious or faulty app to trigger the flaw. No publicly disclosed exploit and the lack of a remote attack pathway reduce the immediate probability of widespread exploitation, but the high impact of a system crash warrants prompt patching.
OpenCVE Enrichment