Impact
An integer overflow in Apple operating systems could be triggered if numeric inputs are not correctly limited. The flaw can cause the system to terminate unexpectedly, which may result in a denial‑of‑service condition. The issue is identified as CWE‑190.
Affected Systems
The vulnerability affects Apple iOS, iPadOS, and macOS. Versions released before iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, or macOS Tahoe 26.7 are vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates medium severity, and the EPSS score of less than 1% shows a low likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. The exploit would rely on an application or input that supplies large numeric values; based on the description, the attack vector is inferred to be through a malicious application or crafted data, but this is not explicitly confirmed in the CVE entry.
OpenCVE Enrichment