Impact
The vulnerability arises from insufficient checks when macOS processes a specially crafted file, which can cause the associated application to terminate unexpectedly and result in a denial‑of‑service condition for that application. The weakness is an input validation flaw, aligning with CWE‑20, as the system fails to validate the file contents before processing.
Affected Systems
Apple’s macOS operating system is affected. Vulnerable versions include any macOS releases prior to macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, and macOS Tahoe 26.4. After those updates the issue is resolved.
Risk and Exploitability
Without an official CVSS score the severity is not quantified, but the impact is limited to the application that opens the crafted file. The likely attack vector is local; a user with the ability to place or open the file can trigger the crash. No publicly disclosed exploits exist, and the vulnerability is not listed in the CISA KEV catalog. It is vulnerable to local exploitation but does not appear to be remotely exploitable at present.
OpenCVE Enrichment