Impact
A vulnerability in macOS allows an attacker to trigger an out‑of‑bounds read by supplying a specially crafted file. The flaw is in data validation when processing the file, leading to unexpected application termination. The attacker cannot gain code execution or elevate privileges, but the application crash can disrupt services or user tasks.
Affected Systems
Apple’s macOS operating system is impacted. The issue has been fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, and macOS Ventura 13.7.7, so any earlier macOS releases remain vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, but the EPSS score of less than 1% shows that it is unlikely to be exploited currently. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation. Attackers would need to supply a malicious file to an application that processes the vulnerable file type, so the attack vector is local or remote file upload, depending on the target application's capabilities.
OpenCVE Enrichment
EUVD