Impact
An out-of-bounds read identified in Apple macOS components was mitigated through improved bounds checking. Triggering the flaw can cause a process to terminate unexpectedly or expose that process’s memory contents. The weakness corresponds to CWE-125, a bounds-checking error that can lead to information disclosure.
Affected Systems
Apple macOS users running releases prior to macOS Golden Gate 27, macOS Sequoia 15.8, or macOS Tahoe 26.7 are affected. These versions contain the vulnerable code; later releases are not impacted.
Risk and Exploitability
The EPSS score is < 1 % and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score is 7.1, indicating a high severity that can result in confidentiality compromise and denial of service. The likely attack vector requires the vulnerable code to execute within the target process, implying a local or application-level exploitation scenario. Given the low exploitation probability, widespread exploitation remains uncertain.
OpenCVE Enrichment