Impact
An integer overflow flaw was identified in several Apple operating systems. The issue arises from inadequate input validation when numeric values are processed, allowing the value to overflow and causing the operating system or a critical component to terminate unexpectedly. The vulnerability was addressed with improved input validation and is fixed in iOS 18.7.10, iPadOS 18.7.10, iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6. An app may be able to trigger the overflow, leading to loss of availability as the affected application or system service crashes and may need a reboot or manual recovery.
Affected Systems
Affected systems include Apple iOS, iPadOS, macOS (Sequoia, Sonoma, Tahoe), tvOS, visionOS, and watchOS. The issue is resolved in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity, while the EPSS score of less than 1% suggests a low likelihood of widespread exploitation at present. The vulnerability is not listed in CISA’s KEV catalog, and no public exploit has been disclosed. Based on the description, it is inferred that the attack vector likely involves a malicious or misbehaving application supplying crafted input locally to trigger the overflow, resulting in service termination.
OpenCVE Enrichment