Impact
The vulnerability is an out-of-bounds read that occurs when memory bounds are insufficiently checked, allowing an application to trigger a system crash. This results in macOS terminating unexpectedly, effectively denying availability to the affected system. The flaw is a classic buffer over-read, which falls under the 'Improper Restriction of Operations within the Bounds of a Memory Buffer' category. If the read is exploited, it can destabilize the entire operating system. The EPSS score of less than 1% suggests a very low but non-zero exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an application can trigger the read, most likely via local interaction, so the primary attack vector is local or opportunistic. The impact remains a denial of service, emphasizing the need for timely remediation.
Affected Systems
The affected systems are macOS operating systems distributed by Apple. Specifically, the flaw exists in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. Software running on these macOS versions is vulnerable if an application triggers the out-of-bounds read.
Risk and Exploitability
The CVSS score for this vulnerability is 5.5, indicating a moderate impact. The EPSS score of less than 1% reflects a low exploitation probability. The vulnerability is not in CISA’s KEV catalog. Exploitation would require local interaction through an application that triggers the vulnerable read operation, leading to an unexpected system crash and denial of service. Because the failure mode is a system termination, the entire OS state may be affected.
OpenCVE Enrichment