Impact
The vulnerability is triggered when macOS processes a specially crafted file that lacks proper bounds checks. Processing such a file can cause the targeted application to terminate unexpectedly, leading to a denial‑of‑service condition for the user of that application. The weakness is represented by heap out‑of‑bounds read (CWE‑125) and a potential use‑after‑free (CWE‑416).
Affected Systems
Apple’s macOS may be affected. Vulnerable releases include any macOS prior to Sequoia 15.7.5, Sonoma 14.8.5, and Tahoe 26.4. The issue has been resolved in those newer OS releases.
Risk and Exploitability
With a CVSS score of 4.3 the severity is moderate, but the EPSS score of less than 1 % indicates a very small likelihood of exploitation under normal circumstances. The attack vector appears to be local, requiring a user to place or open a malicious file; no public exploits or remote exploitation pathways are known. The vulnerability is not listed in the CISA KEV catalog, reflecting its limited exploitation scope.
OpenCVE Enrichment