Impact
This vulnerability is an input validation flaw that caused macOS to accept malformed data without the appropriate checks. The flaw is identified as CWE‑20 and has a CVSS score of 9.8, indicating a severe risk. While the description does not state a specific exploit outcome, the high score suggests that an attacker could potentially cause unintended behavior that might affect system confidentiality, integrity, or availability if the flaw is successfully triggered.
Affected Systems
Apple’s macOS operating systems older than macOS Sequoia 15.4, macOS Sonoma 14.7.5, or macOS Ventura 13.7.5 are impacted because they lack the improved input validation checks introduced in those releases.
Risk and Exploitability
The EPSS score is less than 1 %, indicating very low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Since the flaw relates to how the system processes user‑supplied input, exploiting it would likely involve providing crafted data to a vulnerable component, but the exact attack vector is not listed in the information provided.
OpenCVE Enrichment
EUVD