Impact
This vulnerability is an out-of-bounds read caused by insufficient bounds checking when processing a maliciously crafted 3D file. The flaw allows an attacker to read memory locations beyond the intended buffer, potentially exposing sensitive data stored in memory. The weakness is a classic example of improper memory bounds validation, giving the attacker the chance to retrieve data that should remain private.
Affected Systems
Apple macOS is affected. The issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. Users running earlier releases of these operating systems should update.
Risk and Exploitability
The CVSS base score is 4.3. EPSS score is < 1% and the vulnerability has not been listed in CISA KEV. Because the attack vector requires the user to open a crafted 3D file, local privilege or user interaction is likely needed, lowering the likelihood of exploitation compared, the potential to leak arbitrary memory contents warrants timely remediation.
OpenCVE Enrichment