Impact
The vulnerability allows memory corruption when a malicious accessory connects to a device. Based on the description, it is inferred that the attack requires a physical or local connection of a specially crafted accessory, which can lead to system termination. This impact corresponds to a denial of service, as the operating system crashes and becomes unavailable until reboot.
Affected Systems
Apple devices running iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27 and macOS Tahoe 26.7 are affected. The issue is resolved in newer releases of each platform. The affected platforms include iPhones and iPads with iOS up to 27, iPads with iPadOS up to 27, and Macs with macOS up to 27. Current installations of these operating systems are vulnerable.
Risk and Exploitability
The exploit requires possession of a malicious accessory that can supply crafted input to the device. The EPSS score is < 1%, indicating a very low probability of exploitation in the wild, and the CVSS score of 5.5 reflects a medium severity denial‑of‑service effect. The vulnerability is not listed in the CISA KEV catalog. Although the attack vector is local/physical, the risk to a device in a managed environment is elevated if untrusted accessories are allowed. Until patching, the best mitigation is to avoid using unknown accessories.
OpenCVE Enrichment