Impact
An out‑of‑bounds read occurs when an application reads beyond the intended memory region due to insufficient bounds checking. Apple has addressed this by improving bounds checking, with fixes in iOS 18.7.10, iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6. Until these updates are applied, an attacker could trigger unexpected system termination, effectively denying availability to the user.
Affected Systems
Apple macOS is affected. Versions prior to Sequoia 15.7.8, Sonoma 14.8.8, and Tahoe 26.6 contain the vulnerability; those releases and later include the fix.
Risk and Exploitability
The CVSS score of 9.8 indicates severe impact, yet the EPSS score is < 1% and the flaw is not listed in CISA KEV, suggesting low current exploitation likelihood. It is inferred that the attack vector is local, requiring a malicious application to run with sufficient privileges to trigger the bounds error. The risk can be considered moderate until the update is applied.
OpenCVE Enrichment