Impact
An out‑of‑bounds write issue was addressed with improved bounds checking. Processing a maliciously crafted video file may lead to unexpected app termination, terminating the application or process. This results in a loss of availability rather than code execution or data exposure.
Affected Systems
Apple iOS, Apple iPhone OS, iOS 26.7 and 27; Apple iPadOS, iPadOS 26.7 and 27; Apple macOS, Golden Gate 27, Sequoia 15.8, and Tahoe 26.7; Apple tvOS 27; Apple visionOS 27 are all affected by this out‑of‑bounds write.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation today. The likely attack vector is local or involves a user or service processing a video file, as the description does not mention a remote exploitation condition. The risk is therefore limited to denial of service through application termination, but because the flaw affects a broad range of Apple platforms it could impact mission‑critical or enterprise devices if not patched.
OpenCVE Enrichment