Impact
This vulnerability is a classic buffer overflow (CWE‑119) caused by Apple’s operating systems handling input data without adequate bounds checking. The remote attacker can craft malicious input, leading to unexpected application termination or heap corruption, as stated in the latest description. The flaw is mitigated by improved bounds checking and is fixed in iOS 18.7.10 and 26.6, iPadOS 18.7.10 and 26.6, macOS Sequoia 15.7.8 and Tahoe 26.6, tvOS 26.6, and visionOS 26.6. The vulnerability does not enable remote code execution.
Affected Systems
Apple iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, and visionOS 26.6 are impacted by this flaw.
Risk and Exploitability
The CVSS score of 9.8 indicates high severity, while an EPSS score of <1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to deliver crafted data that exploits the bounds‑checking failure to cause crashes or memory corruption, but the flaw does not provide direct remote code execution.
OpenCVE Enrichment