Impact
The flaw is a memory corruption vulnerability that occurs when Apple iOS, iPadOS, or macOS processes a specially crafted file. The resulting corruption can crash the application that parses the file, leading to an unexpected termination. The weakness is classified as CWE‑1021 and does not grant code execution or privilege escalation, but it can interrupt normal application operation and cause availability loss.
Affected Systems
Apple iOS, iPadOS, and macOS devices running versions prior to 27 (iOS 27, iPadOS 27, and macOS Golden Gate 27) are affected. The fix was introduced in the 27 release, so any device still using an earlier OS is vulnerable to this memory corruption issue.
Risk and Exploitability
The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating a very low current exploitation probability. The CVSS score of 7.8 reflects a high severity for a denial‑of‑service flaw. The likely attack vector is the delivery of a malicious file to the device—e.g., via email attachment, download, or removable media—and its subsequent processing by an application that lacks additional safeguards. Because the flaw does not provide code execution, the primary risk is to application availability rather than to broader system compromise.
OpenCVE Enrichment