Impact
An integer overflow that can be triggered by a maliciously crafted file was discovered in macOS. The flaw allows an attacker to corrupt internal counters, causing the operating system to crash or unexpectedly terminate processes. (The corruption of internal counters is inferred rather than directly specified.) The overflow may also expose memory contents, potentially leaking sensitive data. This vulnerability is a classic integer overrun flaw (CWE‑190) that leads to loss of availability or accidental data exposure.
Affected Systems
The issue affects Apple macOS systems running versions earlier than macOS Golden Gate 27. The fix is implemented in macOS Golden Gate 27 and subsequent releases.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, indicating that no widespread exploitation has been reported to date. The flaw is triggered by a crafted file to the system, so it is a local or file‑based attack vector (inferred). While no public exploit exists, the moderate severity of the integer overflow implies that the risk is non‑negligible if the vulnerable version is deployed.
OpenCVE Enrichment