Impact
The buffer overflow occurs when the macOS kernel processes a connection to a malicious AFP that this leads to kernel memory corruption. Based on the description, it is inferred that gain code execution or elevate privileges, thereby affecting the machine.
Affected Systems
Apple releases of macOS—including Sequoia, Sonoma, and Tahoe—are impacted. Systems running any version prior to Sequoia 15.7.8, Sonoma 14.8.8, or Tahoe 26.6 that use AFPFS for file sharing are potentially exposed.
Risk and Exploitability
The likely attack vector is a malicious AFPFS server that a vulnerable macOS system connects to. When can corrupt memory, potentially leading to remote code execution or privilege escalation. Though the EPSS score indicates a probability of less than in the CISA KEV catalog, the kernel‑level corruption remains a high‑severity risk. Based on the description, attackers could host a rogue AFP server within or adjacent to the target network, ensuring that a vulnerable system automatically connects and triggers the overflow.
OpenCVE Enrichment