Impact
An out‑of‑bounds read flaw, identified by CWE‑125, can be triggered when a maliciously crafted media file is processed. The flaw may cause the target application to terminate unexpectedly or corrupt process memory.
Affected Systems
Apple iOS users should update to iOS 18.7.2 or later, iOS 26.1 or later for older releases. Equivalent updates for iPadOS are 18.7.2 and 26.1; macOS must be upgraded to Sequoia 15.7.2 or Tahoe 26.1; tvOS and visionOS should be updated to version 26.1. These updates include the bounds‑checking fix that prevents the access violation.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate impact. With an EPSS score of less than 1 % the likelihood of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. The exploit requires a local malicious media file; the likely attack vector is a user executing or viewing a corrupted media file. Because memory corruption does not provide direct code execution, the attack surface is limited to causing a crash or corrupting local memory.
OpenCVE Enrichment