Impact
An out‑of‑bounds read in macOS can be triggered by a local application, allowing the read of kernel memory. The resulting disclosure could expose sensitive data or compromise system integrity, and the flaw may also cause the system to terminate unexpectedly. The weakness is identified as CWE‑125.
Affected Systems
Apple macOS versions prior to the security updates listed are affected. The bug is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, and macOS Tahoe 26.1, so all earlier releases of these macOS families remain vulnerable.
Risk and Exploitability
With a CVSS score of 7.8 the flaw is considered high severity. The EPSS score of <1 % indicates a very low probability of exploitation at this time, and the vulnerability is not in the CISA KEV catalog. An attacker would likely need local execution of malicious code, such as an untrusted application, to trigger the out‑of‑bounds read, but once triggered the impact could be data disclosure or system crash.
OpenCVE Enrichment