Impact
An out‑of‑bounds write vulnerability affects multiple Apple operating systems and was addressed by implementing improved bounds checking. The flaw allows a remote attacker to trigger unexpected application termination or heap corruption by writing beyond the allocated memory boundaries. The description highlights that the issue is fixed in several releases: iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, and visionOS 26.6.
Affected Systems
All Apple iOS, iPadOS, macOS, tvOS, and visionOS releases older than iOS 18.7.10, iPadOS 18.7.10, iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, and visionOS 26.6 are implicated, as inferred from the fix releases listed.
Risk and Exploitability
The CVSS score is 9.8, indicating a critical severity, but the EPSS score is <1%, which points to a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector, inferred from the description, is a remote delivery of malicious data that triggers the vulnerable code path, resulting in application termination or heap corruption. No evidence supports more advanced exploitation, such as code execution.
OpenCVE Enrichment