Impact
The vulnerability is an out-of-bounds read in macOS that can cause a system crash. An application that triggers this read can lead to an unexpected termination of the operating system, resulting in a denial of service for that machine. The flaw is a classic out-of-bounds read problem identified as CWE-125.
Affected Systems
Apple's macOS operating system is affected, specifically any release before macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6. Users on earlier versions of these branches may be impacted by the issue.
Risk and Exploitability
The CVSS score of 9.8 classifies the flaw as critical, yet the EPSS score of less than 1% indicates a very low probability that an attacker will successfully exploit it. It is not listed in CISA's KEV catalog. The attack vector is likely local, involving an application that can trigger the out-of-bounds read; however, if the vulnerable code is reachable from the network, remote exploitation is conceivable. The consequence is a crash of the OS, completely interrupting availability on the affected host.
OpenCVE Enrichment