Impact
The flaw originates from missing entitlement checks in Apple Mobile OS, enabling a local application to invoke privileged operations without proper authorization. This can lead to a denial-of-service that disrupts device-wide services and may cause system instability. The weakness is represented by CWE-770 (Uncontrolled Resource Consumption).
Affected Systems
Apple iOS, iPadOS, and visionOS builds prior to iOS 26.7, iPadOS 26.7, and visionOS 27 contain the vulnerability. The fix was released with iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, and visionOS 27. Any device running an earlier build could be affected.
Risk and Exploitability
Based on the description, it is inferred that an attacker would need to install a malicious application on the device to trigger the denial-of-service, because the vulnerability is exercised during local app execution. The CVSS score of 5.5 indicates moderate severity with a local requirement for exploitation. The EPSS score of less than 1% suggests a very low probability of exploitation in the operational environment, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the potential for device-wide service interruption can pose tangible risk to environments where device availability is critical.
OpenCVE Enrichment