Impact
The vulnerability is an out-of-bounds read in Apple operating systems that can lead to unexpected system termination. An application that triggers this read can cause the OS to crash, resulting in a denial of service for that device. This flaw is defined as CWE-125.
Affected Systems
Apple's operating systems, including iOS, iPadOS, and macOS, are affected. Specifically any release before iOS 18.7.10, iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, or macOS Tahoe 26.6. Users on earlier versions of these branches may be impacted by the issue.
Risk and Exploitability
The CVSS score of 9.8 classifies the flaw as critical, yet the EPSS score of less than 1% indicates a very low probability that an attacker will successfully exploit it. It is not listed in CISA's KEV catalog. The likely attack vector is local, involving an application that can trigger the out-of-bounds read; however, if the vulnerable code is reachable from the network, remote exploitation is conceivable. The consequence is a crash of the OS, completely interrupting availability on the affected host.
OpenCVE Enrichment