Impact
An integer overflow in macOS can cause a denial of service by crashing a system component. The flaw occurs when numeric input is not adequately validated, allowing an overflow that disrupts normal operation. The CVE statement indicates that the issue was fixed with improved input validation, implying that the impact is limited to availability and that the description does not mention code execution or privilege escalation. It is inferred that the vulnerability does not enable code execution.
Affected Systems
Apple macOS releases Golden Gate 27, Sequoia 15.8, and Tahoe 26.7 are affected. No other vendors or products are noted in the CNA data. The vulnerability applies to any component of the operating system that processes the vulnerable numeric input on these versions.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score of less than 1% signals a low likelihood of active exploitation, and the vulnerability is not included in the CISA KEV catalog. Attackers would need to supply crafted input to trigger the overflow, so the likely attack vector is inferred to be local or user‑controlled. Because the flaw is limited to denial of service, the risk is manageable but repeated crashes could degrade system availability.
OpenCVE Enrichment