Impact
A buffer overflow occurs when Apple’s operating systems process a maliciously crafted file without proper bounds checking. This defect allows an attacker to cause unexpected application termination or, in some circumstances, execute arbitrary code. The weakness is a classic uncontrolled buffer copy, identified as CWE‑120.
Affected Systems
Apple iOS and iPadOS versions prior to 18.7.10, iOS 26.6, iPadOS 26.6, macOS Sequoia before 15.7.8, and macOS Tahoe before 26.6 are affected. The vulnerability is mitigated in iOS 18.7.10, iPadOS 18.7.10, iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, and macOS Tahoe 26.6.
Risk and Exploitability
The CVSS score of 7.8 classifies the vulnerability as high severity. The EPSS score of < 1% indicates a low exploitation probability, and it is not listed in CISA’s KEV catalog, suggesting limited publicly known exploitation. The likely attack vector is the processing of a maliciously crafted file, which an attacker can supply to a vulnerable application to trigger the overflow and potentially execute arbitrary code.
OpenCVE Enrichment