Impact
A buffer overflow in the disk image mounting process was fixed with improved bounds checking. When a malicious disk image is mounted, the overflow can lead to unexpected system termination. The primary impact is a denial of service, as the affected computer would reboot or crash without providing any data exfiltration or persistence.
Affected Systems
Apple macOS products are affected. Apple lists the bug when it is present in macOS Golden Gate versions earlier than 27, macOS Sequoia earlier than 15.8, and macOS Tahoe earlier than 26.7. The vulnerability is documented as fixed in those specific releases.
Risk and Exploitability
The vulnerability is exploitable by mounting a crafted disk image. This requires the attacker to supply the image to a user or automate the mounting process. The attack vector is inferred to be local or at least requiring the user to initiate the mount. No publicly available exploits have been reported, and the EPSS score is not available, so the likelihood is uncertain.
OpenCVE Enrichment