Impact
An integer overflow occurs when the system processes data that exceeds the limits of an integer variable. This issue was addressed by improving input validation in Apple's operating systems. The flaw, which can be triggered by a malicious application, is fixed in iOS 18.7.10 and 26.6, iPadOS 18.7.10 and 26.6, macOS Sequoia 15.7.8, Sonoma 14.8.8, Tahoe 26.6, and watchOS 26.6. If the vulnerability were present, an attacker could craft data that causes the overflow, enabling the application to break out of its sandbox and potentially access the host operating system or data from other apps.
Affected Systems
Apple devices running iOS, iPadOS, macOS, and watchOS are affected. The vulnerability is fixed in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, and watchOS 26.6. Devices with earlier versions remain at risk.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, while the EPSS score of < 1% suggests a very low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local, with attackers supplying crafted data through a malicious or compromised app already installed on the device. Because the flaw stems from insufficient input validation in a sandboxed component, exploitation would allow the app to escape its sandbox, granting unauthorized access to the host OS and potentially other apps. Updating the OS to the patched releases mitigates the risk and prevents exploitation.
OpenCVE Enrichment