Description
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Parsing a maliciously crafted file may lead to an unexpected app termination.
Published: 2026-07-27
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out-of-bounds read has been identified in macOS when parsing a maliciously crafted file. The flaw arises because the bounds checking was insufficient, allowing the system to read beyond the intended buffer and causing a crash in the application that processed the file. The direct consequence is an unexpected termination of the app, which can temporarily disrupt services or user workflows. This vulnerability is limited to the read operation and does not provide attackers with direct code execution or persistence capabilities, but it can be leveraged to perform denial‑of‑service attacks against affected applications.

Affected Systems

Apple macOS is affected, specifically versions prior to Sequoia 15.7.8, Sonoma 14.8.8, and Tahoe 26.6. Users running these earlier releases should verify their system version and upgrade when the supported patch is issued.

Risk and Exploitability

The CVSS score of 7.1 indicates medium severity. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting that it has not yet been widely exploited in the wild. However, the nature of the flaw – a boundary error triggered by a crafted input – indicates that an attacker could potentially target the system by delivering a malicious file. The likely attack vector is the parsing of such a file, which could be delivered via email attachments, network shares, or other file drop mechanisms. Given the lack of publicly available exploits and the absence of a high‑exploitation probability metric, the risk remains moderate. Users should treat this as a potential cause of service disruption until a patch is applied.

Generated by OpenCVE AI on August 4, 2026 at 23:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install macOS update to version 15.7.8, 14.8.8, or 26.6.
  • If the system cannot be updated immediately, avoid opening or processing suspicious or unknown files by enforcing strict file permissions and validating file integrity before use.
  • If the system remains in an older version, isolate it from external networks and monitor system logs for repeated crashes that may indicate malicious activity.

Generated by OpenCVE AI on August 4, 2026 at 23:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in macOS Causing Unexpected App Termination
Weaknesses CWE-788

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in macOS Causing Unexpected App Termination
Weaknesses CWE-125
CWE-788
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Parsing a maliciously crafted file may lead to an unexpected app termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T13:40:38.554Z

Reserved: 2026-05-01T22:46:21.647Z

Link: CVE-2026-43747

cve-icon Vulnrichment

Updated: 2026-07-28T13:40:29.964Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:16:59.450

Modified: 2026-07-28T19:52:50.603

Link: CVE-2026-43747

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T23:45:02Z

Weaknesses