Impact
An app can trigger a denial‑ checks that should restrict certain OS functions. The flaw allows any application that has obtained general installation rights to send requests that overwhelm or crash target system threads, leading to a disruption of device functionality. The impact is limited to service interruption and does not disclose or modify data.
Affected Systems
Apple iOS versions prior to 26.7, iPadOS versions prior to 26.7, and visionOS versions prior to 27 are affected. The issue was resolved in iOS 26.7 and 27, iPadOS 26.7 and 27, and visionOS 27, so any device running an older build could potentially be compromised.
Risk and Exploitability
The vulnerability is exploitable from within a local application context; an attacker would need to install a malicious app on the device. No EPSS or KEV data is available, and the CVSS score is not disclosed, but because the flaw permits a device‑wide DoS, the risk is tangible for environments where device availability is critical. The attack path requires only user‑level privileges granted by the OS to the app, so no elevated permissions are needed.
OpenCVE Enrichment