Impact
A buffer overflow was addressed with improved size validation in a core component. This issue was fixed in iOS 18.7.10 and iPadOS 18.7.10, in iOS 26.6 and iPadOS 26.6, and in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6. An app may be able to execute arbitrary code with kernel privileges. The vulnerability is caused by an incorrect size validation that leads to a buffer overflow, which a malicious or compromised application can exploit to gain kernel‑level execution.
Affected Systems
The flaw impacts Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS versions released before the patched releases listed in the Apple advisory. Specifically, all iOS and iPadOS versions prior to 18.7.10 and those older than 26.6, macOS Sequoia before 15.7.8, macOS Sonoma before 14.8.8, macOS Tahoe before 26.6, tvOS before 26.6, visionOS before 26.6, and watchOS before 26.6 are potentially vulnerable. The patched releases listed have addressed the issue.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity vulnerability, and the EPSS score of <1% suggests a very low but non‑zero probability of exploitation. It is not listed in CISA’s KEV catalog. The flaw allows kernel‑level code execution, effectively giving the attacker full control of the device. The likely attack vector is inferred to be local, requiring the attacker to run a malicious or compromised app that can trigger the buffer overflow.
OpenCVE Enrichment