Impact
A flaw in macOS can cause the processing of a maliciously crafted image to expose fragments of a process’s memory, revealing confidential data such as cryptographic keys or passwords. This vulnerability is defined as an information‑exposure flaw (CWE‑200) and does not provide arbitrary code execution.
Affected Systems
The issue affects all macOS releases prior to Sequoia 15.6. Apple implemented mitigations in macOS Sequoia 15.6, correcting the flawed checks that allowed unvalidated image data to cause memory disclosure.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate risk, while an EPSS score of less than 1 % implies a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog, and the description does not specify any access or privilege requirements; the attack appears to rely simply on supplying a crafted image to the image‑processing subsystem.
OpenCVE Enrichment
EUVD