Impact
The vulnerability is an out‑of‑bounds write that occurs while processing disk images. When a malicious image is mounted, the unchecked write can corrupt memory, leading to an unexpected system termination. The primary consequence is loss of availability for the affected machine, as the crash forces the system to reboot or become unresponsive.
Affected Systems
Apple macOS releases prior to Sequoia 15.7.8, Sonoma 14.8.8, and Tahoe 26.6 are affected. Users running any earlier version of those macOS code names are vulnerable; the issue is addressed in the listed update releases.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.5, an EPSS score of less than 1%, and is not listed in the CISA KEV catalog, indicating no known widespread exploitation at this time. Attackers could trigger the fault by submitting a crafted disk image, and the likely attack vector is local mounting of the disk image; the CVE does not specify a remote exploitation path. Because the failure results in a crash rather than code execution, the risk is lower than for a vulnerability that provides remote code execution.
OpenCVE Enrichment