Impact
This vulnerability is a use‑after‑free flaw classified as CWE‑416. A maliciously crafted SMB network share can trigger the flaw in macOS’s memory management, resulting in an unexpected system crash. The primary impact is a denial of service: the operating system terminates, causing loss of availability for all running applications and potentially disrupting critical services.
Affected Systems
Apple’s macOS operating system is affected. The flaw is present in all releases prior to the security updates listed in Apple’s documentation: macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, and macOS Tahoe 26.4. Users running any earlier version of these macOS releases are susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. Exploit probability is low, with an EPSS score of less than 1%, and the vulnerability is not catalogued in the CISA KEV list. Attackers would need to gain network access to deliver a malicious SMB share. Although the CVE does not explicitly state an attack vector, the description suggests a remote exploitation path via the SMB protocol.
OpenCVE Enrichment