Impact
An out‑of‑bounds read was discovered in Apple’s operating systems due to inadequate bounds checking. The flaw can be triggered by an application, causing the system to terminate unexpectedly. The vulnerability is fixed in iOS 18.7.10, iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6. The result is a denial of service for all users of the affected systems.
Affected Systems
Apple iOS, iPadOS, and macOS are affected. The issue has been remedied in iOS 18.7.10, iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6. Any earlier releases that do not include these patch fixes remain vulnerable.
Risk and Exploitability
The EPSS score indicates a very low exploitation probability (less than 1%) and the vulnerability is not listed in the CISA KEV catalog, implying no significant widespread exploitation activity is documented. The CVSS score is 9.8, reflecting a high impact in terms of availability. The likely attack vector is local, as the description notes that an app may trigger the error; however, without additional details, precise conditions for exploitation remain uncertain. Given the potential for denial of service, the risk warrants prompt remediation.
OpenCVE Enrichment