Impact
The vulnerability is a bounds‑checking flaw that allows an out‑of‑bounds write during the parsing of a maliciously crafted image, leading to memory corruption. The effect can manifest as application crashes or other instability; the CVE description does not explicitly confirm that arbitrary code execution or elevated privileges can be achieved, but memory corruption may provide an initial foothold for further exploitation if additional weaknesses exist.
Affected Systems
Apple devices running iOS or iPadOS prior to 26.7, Sequoia before 15.8 and Tahoe before 26.7—plus tvOS and visionOS versions older than 27 are affected. These systems lack the updated bounds checking that was introduced in the listed new releases and therefore remain vulnerable to image‑based malicious input.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, and the EPSS score of < 1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, implying no publicly known exploits to date. The attack vector is inferred to be the delivery of a malicious image to any component that accepts image input; no additional conditions are required beyond this input. While the impact primarily involves memory corruption and potential crashes, this could serve as a pre‑condition for more serious attacks if other vulnerabilities are present.
OpenCVE Enrichment