Impact
An out‑of‑bounds read occurs when the operating system processes a maliciously crafted media file. The flaw can cause the application to terminate unexpectedly or corrupt process memory, potentially leading to instability or exploitation of corrupted data. The primary impact is memory corruption, which may allow an attacker to influence application behavior or leverage the corrupted memory for further attacks.
Affected Systems
Apple • iOS (fixed in iOS 18.7.2 and 26.1) • iPadOS (fixed in iPadOS 18.7.2 and 26.1) • macOS (fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1) • tvOS (fixed in tvOS 26.1) • visionOS (fixed in visionOS 26.1) • watchOS (fixed in watchOS 26.1)
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity and the EPSS score is under 1 %, showing a very low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the delivery and processing of a malicious media file; the attack requires the attacker to supply such a file to the system. The description does not indicate direct remote code execution or privilege escalation, only application crash or corruption of process memory.
OpenCVE Enrichment