Impact
A validation flaw caused by inadequate input sanitization allows an attacker to trigger arbitrary code execution or unexpected termination of an application. The weakness is a classic improper input handling problem (CWE‑20). The vulnerability can be exercised remotely by delivering specially crafted data to the affected application, which may run arbitrary code with the app’s privileges.
Affected Systems
Apple macOS systems running versions earlier than macOS Golden Gate 27, macOS Sequoia 15.8, or macOS Tahoe 26.7 are impacted. All preceding releases of these macOS lines remain vulnerable until updated.
Risk and Exploitability
With a CVSS score of 8.8 the severity is high, but the EPSS score of less than 1 % indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote; a crafted payload could lead to code execution on the host if the vulnerability is triggered.
OpenCVE Enrichment