Impact
The vulnerability is a classic buffer overflow (CWE‑120) that occurs when an application writes data beyond the bounds of an internal kernel buffer. The flaw is caused by a missing bounds check, allowing the overflow to modify adjacent kernel memory. A malicious program or exploit that triggers the overflow can crash the system or write arbitrary data to kernel memory, potentially corrupting critical structures and enabling a denial‑of‑service or privilege‑escalation attack.
Affected Systems
Apple iOS releases prior to 26.6, iPadOS prior to 26.6, macOS Sequoia prior to 15.7.7, macOS Sonoma prior to 14.8.7, and macOS Tahoe prior to 26.6 are affected. Any device running an earlier build of these operating systems could be susceptible to the overflow if the vulnerable code path is executed.
Risk and Exploitability
Based on the description, it is inferred that the attack vector is local—requiring the execution of a trigger application. The EPSS score is low (< 1%), and the vulnerability is not listed in CISA KEV, indicating minimal publicly known exploitation data. The CVSS score of 5.5 indicates a moderate severity; however, because the attack vector appears to be local—requiring the presence of a trigger application—the risk to systems that do not run compromised or malicious local applications is reduced. The described impact could lead to denial‑of‑service or privilege escalation, but exploitability depends on the ability to run the vulnerable code with sufficient privileges.
OpenCVE Enrichment