Impact
This vulnerability is an integer overflow that can be triggered by malformed input in certain macOS components. The overflow causes a crash of the system or affected application, resulting in an unexpected system termination. The impact is a denial of service that disrupts user sessions and can affect critical processes.
Affected Systems
The issue affects Apple macOS operating systems older than Sequoia 15.7.8, Sonoma 14.8.8, and Tahoe 26.6. Versions before these releases are vulnerable; the problem is addressed in Sequoia 15.7.8, Sonoma 14.8.8, Tahoe 26.6 and later updates.
Risk and Exploitability
The EPSS score of less than 1% and a CVSS score of 9.8 indicate a low probability of exploitation but a high potential impact. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. The likelihood of remote exploitation appears low, as the attack likely requires local execution of an application that processes large integer inputs, yet the high severity underscores the need to apply the fix promptly.
OpenCVE Enrichment