Impact
A malicious application may trigger a buffer overflow in macOS, which can lead to unexpected system termination. The flaw is identified as CWE‑120, involving improper bounds checking during memory operations. The primary consequence of exploitation is a crash of the operating system, which disrupts availability and can result in data loss or interruption of critical services.
Affected Systems
Apple macOS versions prior to Sequoia 15.4, Sonoma 14.7.5, and Ventura 13.7.5 are affected. Devices running those releases are vulnerable; the issue is fixed in the listed newer releases.
Risk and Exploitability
The CVSS score of 9.8 classifies this vulnerability as Critical, yet the EPSS score of less than 1 % indicates a very low probability of exploitation at the present time. It is not listed in the CISA KEV catalog. The attack vector is likely local, involving a malicious application that can cause the overflow, but no explicit network or remote exploitation scenario has been described in the available data.
OpenCVE Enrichment
EUVD