Impact
A memory management flaw allows an attacker to craft a file that, when processed by the operating system, triggers an out‑of‑bounds read. This can cause the system to crash, resulting in a denial‑of‑service, or expose sensitive memory contents, leading to information disclosure. This vulnerability corresponds to CWE‑125.
Affected Systems
Apple devices running iOS, iPadOS, macOS, tvOS, visionOS, or watchOS are affected. The vulnerability is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, and watchOS 26.3.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate severity and the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires delivery of a malicious file to the victim’s system and processing by an application that typically runs with elevated privileges; this inference is made because the description does not explicitly state the privilege level or the application involved, and the scenario does not require network access or user interaction beyond opening or handling the file. Consequently, the risk is moderate but mitigated by the low exploitation probability.
OpenCVE Enrichment