Impact
The CVE describes a memory corruption vulnerability in Apple’s implementation of the Apple Filing Protocol (AFP). A client that connects to a malicious AFP server can cause a buffer overflow, corrupting kernel memory. This memory corruption could enable an attacker to execute arbitrary code with kernel privileges; based on the description, it is inferred that such an escalation is possible but not explicitly confirmed.
Affected Systems
Apple macOS versions prior to Sequoia 15.5 and Sonoma 14.7.6 are known to be affected, as the issue is fixed in those releases. No explicit statement covers newer releases, so any versions beyond those are not confirmed to be affected.
Risk and Exploitability
The CVSS score of 8.8 classifies the flaw as high‑severity. The EPSS score of less than 1 % indicates that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. The attack vector requires a network connection to an AFP server, so remote access via AFP communications is the expected trigger.
OpenCVE Enrichment
EUVD