Impact
The vulnerability is caused by insufficient bounds checking when processing a maliciously crafted file, which can trigger an unexpected application termination. This flaw leads to an out-of-bounds memory access (CWE-119) but does not provide a code‑execution vector. An attacker could repeatedly crash an application by supplying specifically constructed files to the vulnerable components.
Affected Systems
Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are affected. The issue is fixed in iOS 18.7.9, iOS 26.5, iPadOS 18.7.9, iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, and watchOS 26.5.
Risk and Exploitability
The CVSS score of 6.2 indicates a medium severity vulnerability, and the EPSS score of < 1% indicates a low probability of exploitation. The flaw requires a malicious, locally crafted file to trigger an application crash, limiting the attack surface to users or processes that open such files. The vulnerability is not listed in the KEV catalog, and no exploitation reports are known. Overall, it poses a medium denial‑of‑service risk for affected applications.
OpenCVE Enrichment