Impact
The vulnerability stems from an integer overflow that was addressed by applying improved input validation in recent Apple OS releases. When an application processes a maliciously crafted file, the overflow can cause the application to terminate unexpectedly or enable arbitrary code execution within the app’s context.
Affected Systems
Apple’s operating systems—iOS, iPadOS, macOS (Sequoia 15.7.8, Sonoma 14.8.8, Tahoe 26.6), tvOS, visionOS, and watchOS—are affected. The flaw exists in each version prior to the corresponding 26.6 or 15.7.8/14.8.8/26.6 update; devices running earlier releases remain vulnerable.
Risk and Exploitability
CVSS score of 7.8 indicates high severity. The EPSS score of less than 1% suggests a low current likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, implying no publicly known exploits. The attacker must supply a specially crafted file, which is likely delivered via email attachments, malicious downloads, or embedded in a third‑party app. Based on the description, the attack vector is local or user‑initiated file processing; no remote trigger is documented.
OpenCVE Enrichment