Impact
A flaw in macOS's memory handling can allow an application to corrupt memory, potentially leading to unexpected system termination or process corruption. This vulnerability, classified as CWE-787, reflects an out‑of‑bounds write that can overwrite critical data structures. The result is loss of process integrity and, in severe cases, a system crash.
Affected Systems
Apple macOS releases prior to macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, and macOS Tahoe 26.1 are vulnerable. All earlier versions of these operating systems remain susceptible until the corresponding patches are installed.
Risk and Exploitability
The CVSS score of 7.8 marks this as a high‑severity flaw, yet the EPSS of less than 1% indicates a very low probability of exploitation at this time. The vulnerability is not present in the CISA KEV catalog, further suggesting limited exploitation activity. Based on the description, the attack vector is local, requiring an application that triggers the memory corruption. An attacker would need to deliver or execute a privileged or user‑level application that reaches the vulnerable code path to cause a crash or corrupt memory.
OpenCVE Enrichment