Impact
A flaw in macOS memory handling can allow an application to cause the operating system to terminate unexpectedly or to write to kernel memory. The vulnerability could lead to a compromise of system integrity and stability, potentially allowing an attacker to execute arbitrary code with kernel privileges if they have the ability to trigger the flaw. The description emphasizes kernel memory access and system crashes, indicating a severe impact on confidentiality, integrity, and availability.
Affected Systems
Apple macOS systems are susceptible. The issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6. Devices running earlier releases of these macOS versions are therefore vulnerable.
Risk and Exploitability
The CVSS score is 9.8, indicating critical severity. The EPSS score is less than 1%, suggesting a low probability of exploitation at this time. The vulnerability is not listed in CISA KEV. Based on the description, the attack vector is likely local or requires an application to be executed with user privileges that can invoke the vulnerable memory handling code. Exploitation would involve triggering the fault that results in a system crash or a kernel memory write, potentially allowing an attacker to gain kernel privilege if successful.
OpenCVE Enrichment