Impact
This issue arises from insufficient validation when processing a specially crafted file, potentially causing the system to crash or revealing sensitive memory contents. The vulnerability can result in a denial‑of‑service condition or, in the worst case, information disclosure, compromising data confidentiality. No code execution attack is reported.
Affected Systems
Apple iOS and iPadOS devices are affected, as are macOS systems running Sequoia 15.7.7 or Tahoe 26.5. Applications or system components that handle user‑supplied files on these platforms could trigger the flaw before the 18.7.9 (iOS/iPadOS) or 15.7.7/26.5 (macOS) updates are installed.
Risk and Exploitability
Deploying a maliciously crafted file to the device is required; it does not depend on remote network access. The CVSS score of 7.1 reflects a high severity. The EPSS score of 0.00017 indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the possibility of denial of service or memory exposure still poses an operational risk until the vendor’s update is applied.
OpenCVE Enrichment