Impact
An integer overflow flaw exists in the file processing routines of Apple operating systems. The issue was mitigated by adding stricter input validation, and it is fixed in iOS 18.7.10, iPadOS 18.7.10, iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6. When a maliciously crafted file is processed, the overflow can cause an application to terminate unexpectedly or, in some cases, allow an attacker to execute arbitrary code. This flaw is classified as CWE-190: Integer Overflow or Wraparound.
Affected Systems
Apple devices running iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are affected. The flaw is mitigated in iOS 18.7.10, iPadOS 18.7.10, iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, and the EPSS score of under 1% shows a low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the updated description, it is inferred that the attack vector involves the delivery of a malicious file that an application processes, potentially requiring the file to be executed by a privileged or system component. This risk is particularly high for users who accept or download untrusted content.
OpenCVE Enrichment