Impact
An integer overflow flaw was discovered in several Apple operating systems. When a maliciously crafted file is processed, the system allocates memory incorrectly, potentially exposing the contents of process memory. This weakness is a classic integer overflow (CWE‑190) that leads to a data disclosure vulnerability.
Affected Systems
The vulnerability affects devices running iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27. Earlier versions of these operating systems remain vulnerable until patched.
Risk and Exploitability
The vulnerability can lead to disclosure of process memory, but the CVSS score is 6.5, indicating a moderate impact. The EPSS score is below 1%, implying a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a maliciously crafted file, so the attack vector is likely local or remote file upload, depending on context. Devices that frequently accept untrusted files, such as macOS systems with Gatekeeper disabled, present the highest risk.
OpenCVE Enrichment