Impact
An out-of-bounds read was identified in macOS, leading to a vulnerability that could allow a remote attacker to cause buffer read beyond the boundary, classified as CWE‑125. The description states that a remote attacker may trigger a crash, but it does not specify whether user interaction is required; this is inferred to likely not require user interaction.
Affected Systems
Apple macOS systems running pre‑release versions prior to macOS Golden Gate 27, macOS Sequoia 15.8, or macOS Tahoe 26.7 are impacted. The vulnerability was addressed in those releases and later.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, while the EPSS score of < 1% indicates a very low but non‑zero probability of exploitation, making the exact exploitation likelihood uncertain. The vulnerability appears to be remotely exploitable, as a remote attacker may trigger a crash by manipulating the input that triggers the out‑of‑bounds read. It is not listed in the CISA KEV catalog, and publicly known exploits have not yet been confirmed, though the potential impact on affected systems remains significant.
OpenCVE Enrichment