Impact
The vulnerability is an unvalidated memory handling flaw that enables an application to trigger a crash of the macOS kernel or key system services. This defect is rooted in multiple buffer over/underflow weaknesses—specifically CWE‑119, CWE‑125, and CWE‑787. When triggered, the system exits abruptly, causing a denial of service that affects all running processes and services, though it does not directly compromise confidentiality or integrity.
Affected Systems
Apple distributes the affected macOS releases prior to Sequoia 15.7.8, Sonoma 14.8.8, and Tahoe 26.6, which are the versions in which the issue was corrected. Any macOS installation matching or older than these release series remains vulnerable until a patch or upgrade is applied.
Risk and Exploitability
The publicly available data does not indicate any active exploit, and the EPSS score is reported as less than 1 %. The CVSS score of 5 reflects medium severity. The vulnerability is not listed in CISA’s KEV catalog, underscoring its current low exploitation probability. Based on the description, exploitation would require local execution of malicious code—such as a specially crafted application or script—that exercises the faulty memory handling paths. Consequently, the risk is primarily to systems that run untrusted or third‑party software, and the impact is a loss of availability with potential downtime until a reboot or patch is applied.
OpenCVE Enrichment