Impact
An out‑of‑bounds write flaw exists in the file‑processing component of Apple operating systems. The weakness is a classic buffer bounds violation (CWE‑787). When a maliciously crafted file is processed, the flaw causes an unexpected application termination rather than normal operation, leading to a denial of service within the affected application.
Affected Systems
Apple iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, and visionOS 27 are vulnerable. The issue is removed in the higher releases listed in the vendor advisories; earlier versions remain susceptible.
Risk and Exploitability
The CVSS score of 4.3 signals a low severity impact. The EPSS score of less than 1% indicates a very low probability of mass exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only a specially crafted file that is processed locally; no elevated privileges or network access are described, so the attack vector is likely limited to local or user‑initiated file handling. Though unlikely to affect a large number of systems, the impact is real for users who run applications that process untrusted files and which may experience involuntary service interruption.
OpenCVE Enrichment