Impact
An out-of-bounds read (CWE-125) occurs when macOS processes a maliciously crafted USD file, allowing an attacker to read arbitrary memory contents. The primary consequence is the disclosure of potentially sensitive data, but it does not provide code execution or privilege escalation capabilities.
Affected Systems
Apple macOS installations prior to Sequoia 15.6 are vulnerable, including all earlier Sequoia releases and older macOS versions.
Risk and Exploitability
The CVSS score of 5.5 marks this as a moderate‑severity information‑disclosure flaw. The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The attack likely requires delivery of a crafted USD file to the target system, which may be done locally or via remote channels such as email or download. Based on the description, the attack vector is inferred to be file inclusion rather than network exploitation.
OpenCVE Enrichment
EUVD