Impact
An out-of-bounds write flaw, classified as CWE-787, exists in several Apple operating systems and allows an attacker to write beyond a buffer’s boundaries. The vulnerability can be triggered by a specially crafted input to the vulnerable component and may lead either to unexpected application termination or, in the worst case, to the execution of arbitrary code with the privileges of the affected process.
Affected Systems
Apple iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27 are all affected. Devices running any of these OS releases are vulnerable until updated to the patched versions.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. The EPSS score is less than 1%, which implies a low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation has not been observed. The likely attack vector is remote; an attacker must deliver a crafted payload to the vulnerable component, after which the flaw can cause a crash or allow code execution.
OpenCVE Enrichment