Impact
The vulnerability is a race condition in state handling that allows a malicious application to cause the device to terminate unexpectedly, resulting in a denial‑of‑service. The flaw stems from improper synchronization of concurrent state transitions and is categorized as CWE‑362. An attacker with local access capable of installing a specially crafted application can trigger the race, leading to a system crash.
Affected Systems
The flaw affects all recent releases of Apple’s operating systems where the fix has not yet been deployed. This includes iOS 26.7 and iOS 27, iPadOS 26.7 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27. Devices running any of these versions or earlier unsupported releases may be vulnerable unless they have applied the corresponding update.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate severity, while the EPSS score of less than 1% points to a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, which implies no publicly known exploits. The attack vector is inferred to be local, requiring the adversary to install a malicious application or otherwise execute code on the device. Consequently, the overall risk remains limited by the local nature of the exploit and the low intervention probability.
OpenCVE Enrichment