Impact
The vulnerability arises from insufficient bounds checking when parsing a file on Apple operating systems. A maliciously crafted file can cause an application to terminate unexpectedly, delivering a denial of service to users interacting with the affected app.
Affected Systems
Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. Versions older than 26.6 are susceptible; all listed platforms include the corrective changes in 26.6 or later.
Risk and Exploitability
The CVSS score is 7.8, indicating high severity. The EPSS score is below 1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, signifying no publicly known exploitation. An attacker would need to supply a specifically crafted file to a target device; the impact is limited to application termination without privilege escalation or data breach.
OpenCVE Enrichment