Impact
An integer overflow was identified where an application could cause unexpected system termination. This issue was addressed with improved input validation and is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6. The flaw results from insufficient input validation and is classified as CWE-190.
Affected Systems
Apple macOS platforms prior to macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6 are vulnerable. The fix is included in those releases and later.
Risk and Exploitability
The CVSS score of 9.8 reflects a critical severity, while the EPSS score is < 1% indicating a low probability of exploitation. The vulnerability can be leveraged by a local or privileged application to crash the entire system, causing a denial‑of‑service event. No public exploits have been reported, and it is not listed in CISA KEV.
OpenCVE Enrichment