Impact
A memory corruption flaw in Apple operating systems was addressed by removing the vulnerable code paths. Processing a maliciously crafted image can lead to arbitrary code execution, allowing an attacker to control the affected device. The vulnerability stems from improper handling of image data, resulting in memory corruption that can be leveraged to jump to attacker supplied code.
Affected Systems
Apple iOS and iPadOS, Apple macOS Golden Gate, and Apple visionOS devices running versions prior to 27 are affected. The issue was fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, and visionOS 27.
Risk and Exploitability
The CVSS score is not publicly disclosed, and the EPSS score is unavailable, but the exploitability is high because arbitrary code execution can be achieved by feeding a crafted image to the system. The likely attack vector would involve an attacker providing a malicious image through a user‑initiated action such as opening a file, viewing a link, or installing an app that manipulates image data. The lack of a KEV listing suggests but the potential for exploitation remains significant given the nature of the flaw.
OpenCVE Enrichment