Impact
The vulnerability involves a CWE‑20 input validation flaw in Apple iOS and iPadOS that can be triggered by a malicious actor within radio range. When exploited, the flaw can lead to unexpected system termination, effectively causing a denial‑of‑service condition on the affected device. The issue was corrected in iOS 27 and iPadOS 27.
Affected Systems
Apple iOS and iPadOS systems prior to release of version 27 are affected. The flaw is fixed in iOS 27 and iPadOS 27.
Risk and Exploitability
With a CVSS score of 6.5, the vulnerability presents a moderate severity level, while the EPSS score below 1% indicates a low probability of exploitation. The vulnerability is not listed in CISA KEV. The radio‑based attack vector suggests that an attacker must be in close proximity to victim devices. Because the issue is mitigated in the latest releases, the risk is limited to devices that have not yet been updated. For unpatched devices, an attacker in range could trigger an unexpected system termination, leading to a denial‑of‑service condition and potentially facilitating additional attacks if service disruption is a critical concern.
OpenCVE Enrichment