Impact
The vulnerability is an input validation flaw classified as CWE‑20. An application can supply malformed data that triggers a denial‑of‑service condition, causing the system or applications to crash or become unresponsive. This results in a loss of availability for the affected host.
Affected Systems
Apple macOS releases prior to Sequoia 15.7.3, Sonoma 14.8.3, and Tahoe 26.2 are vulnerable. Upgrading to any of those patched releases eliminates the flaw.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. An EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local or requires a malicious application; based on the description, it is inferred that no remote exploitation path is disclosed.
OpenCVE Enrichment