Impact
Improper handling of video decoding causes memory corruption or unexpected application termination when a malicious video file is processed. The vulnerability is a buffer handling fault (CWE‑119) and results in corrupt process memory but does not provide a documented mechanism for arbitrary code execution or remote exploitation.
Affected Systems
Apple iOS 26.6 and 26.7, iPadOS 26.6 and 26.7, macOS Sequoia 15.8, mac Tahoe 26.6 and 26.7, tvOS 26.6, and watchOS 26.6 are affected. Versions newer than those listed contain the fix.
Risk and Exploitability
The CVSS score of 7.8 indicates moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. It is triggered by a local, user‑controlled input—a malicious video file—so the most likely attack vector involves a social‑engineering scenario where a user opens a hostile file. Exploitation leads to memory corruption and application crash or unstable behavior, but there is no evidence of remote or arbitrary code execution.
OpenCVE Enrichment