Impact
A remote attacker can exploit improper memory handling in macOS kernel to corrupt kernel memory or terminate the operating system unexpectedly. The flaw is a classic buffer overflow and out‑of‑bounds write (CWE‑787) that can compromise system integrity and availability, potentially allowing further privileged malicious actions.
Affected Systems
Apple’s macOS is affected. The vulnerability exists in Golden Gate 27, Sequoia 15.8, and Tahoe 26.7. Users of any of these releases are vulnerable until they apply the fix in a newer release.
Risk and Exploitability
The CVSS score of 9.1 reflects a high severity. EPSS indicates a very low probability of exploitation (<1%). The vulnerability is not yet listed in CISA KEV. It is inferred that the attack vector is remote, likely requiring an ability to deliver crafted input that manipulates kernel memory, but no public exploit is documented.
OpenCVE Enrichment