Impact
The vulnerability is an out‑of‑bounds read that allows a remote attacker to trigger an unexpected termination of a benign application. The flaw arises when insufficient input validation permits reading beyond valid memory. The impact is strictly the denial of service caused by the application crash; no external memory disclosures or code execution are implied by the description.
Affected Systems
iOS and iPadOS are affected, with the flaw present in versions 18.7.10 and 26.6. macOS is impacted in Sequoia 15.7.8, Sonoma 14.8.8, and Tahoe 26.6. tvOS and visionOS are vulnerable in version 26.6. Upgrading to any of those releases or later ones incorporates the patch that introduces stricter input validation, thereby resolving the issue.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. The EPSS score of < 1 % signals a very low, though non‑zero, probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no public exploitation reports yet. Based on the description, the likely attack vector is remote application‑level input; an attacker can craft data to trigger the out‑of‑bounds read and induce a crash, denying service to legitimate users.
OpenCVE Enrichment