Impact
A buffer overflow due to insufficient bounds checking could allow an application to overwrite kernel memory or cause an unexpected system termination. The overflow may lead to system instability or compromise the integrity of the operating system, potentially enabling escalated privileges if the attacker can inject or alter kernel data structures. The vulnerability allows direct memory manipulation at the kernel level, which is a severe weakness.
Affected Systems
Apple macOS releases prior to Sequoia 15.7.7 and Sonoma 14.8.7 are affected. Any system running an earlier build of these macOS versions could be susceptible to the overflow if within the affected code paths is executed.
Risk and Exploitability
Based on the description, it is inferred that the attack vector is local—requiring the execution of a trigger application. The EPSS score is not available and the vulnerability is not listed in CISA KEV, indicating limited publicly known exploitation data as of this analysis. The CVSS score of 5.5 indicates a moderate severity; however, because the attack vector appears to be local—requiring the presence of a trigger application—the risk to systems that do not run compromised or malicious local applications is reduced. The described impact could lead to denial‑of‑service or privilege escalation, but exploitability depends on the ability to run the vulnerable code with sufficient privileges.
OpenCVE Enrichment