Impact
The vulnerability is a bounds‑check flaw that can be triggered by a maliciously crafted string, resulting in heap corruption.
Affected Systems
All Apple macOS releases prior to macOS Sequoia 15.7, macOS Sonoma 14.8, and macOS Tahoe 26 are affected; the issue is fixed in those releases and later versions.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA KEV. The likely attack vector involves the processing of a maliciously crafted string by an affected component.
OpenCVE Enrichment
EUVD