Impact
A malicious application can exploit a memory handling flaw to corrupt the memory space of a privileged system process, potentially leading to arbitrary code execution or compromise of system integrity.
Affected Systems
Apple macOS operating systems prior to macOS Sonoma 14.8.8 and macOS Tahoe 26.6 contain the vulnerable memory handling code and are therefore susceptible to exploitation.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, while the EPSS score of < 1% suggests a low likelihood of exploitation in the wild; the vulnerability is not listed in the CISA KEV catalog, implying no known mass exploitation. Crafting a malicious app that targets the vulnerable memory handling code offers a feasible attack path, and if successful, an attacker could achieve arbitrary code execution or privilege escalation within the system.
OpenCVE Enrichment