Impact
According to the updated description, a buffer overflow occurs when the operating system parses a 3D model, allowing the reading of memory beyond intended bounds. This flaw can leak data normally kept private, exposing sensitive information that could be accessed by an attacker.
Affected Systems
Apple’s iOS and iPadOS versions before 18.7.10 and before 26.6, macOS Sequoia before 15.7.8, and macOS Tahoe before 26.6 are affected by this flaw.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity. The EPSS score of <1% shows a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be local or remote if an attacker can supply a crafted 3D model to the target system. Successful exploitation would let an attacker read arbitrary data from the victim’s process memory, potentially compromising sensitive information. While the likelihood of exploitation is low, the impact of a successful breach can be significant.
OpenCVE Enrichment