Impact
A bounds‑checking failure in the image parsing subsystem of Apple operating systems causes a memory corruption flaw. The flaw, identified as a buffer overrun (CWE‑119), can be triggered by a maliciously crafted image. When the parser processes such an image, it corrupts memory and typically crashes the image‑processing component, leading to a denial‑of‑service to the affected application or, if the crash propagates, to the entire system.
Affected Systems
Apple iOS versions older than 18.7.10, iPadOS versions older than 18.7.10, macOS Golden Gate releases prior to 27, macOS Sequoia prior to 15.7.8, and macOS Sonoma prior to 14.8.8 are vulnerable. Updating any of these systems to the specified fixed releases or newer removes the memory corruption flaw.
Risk and Exploitability
The attack vector is inferred from the description: an adversary can supply a maliciously crafted image through any channel that loads images, such as email attachments, web pages, or in‑app galleries. The CVSS score of 5.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low current exploitation probability; furthermore, the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because the flaw can trigger a system crash or application termination, it remains a legitimate risk that warrants prompt patching.
OpenCVE Enrichment