Impact
An improper memory handling flaw in macOS can be exploited by an application to trigger a denial-of-service condition, causing the system or specific services to crash or become unresponsive. The weakness capitalizes on resource exhaustion or buffer mismanagement, classified as CWE‑400, and allows an attacker to degrade system availability rather than compromising confidentiality or integrity.
Affected Systems
Apple macOS installations prior to the release of Sequoia 15.6 are affected. The fix was introduced in macOS Sequoia 15.6, so any version older than 15.6 remains vulnerable and should be updated.
Risk and Exploitability
The main risk is service disruption, which could impact user productivity or critical workflows. The CVSS score of 5.5 denotes medium severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a locally or remotely delivered application that triggers the flaw, so both end‑user and network attackers could potentially induce a crash if they can execute code on a vulnerable device.
OpenCVE Enrichment
EUVD