Impact
A buffer overflow caused by insufficient bounds checking allows a crafted input to exceed allocated memory boundaries, which can trigger the operating system to terminate unexpectedly. The flaw is limited to a denial‑of‑service effect and does not provide privilege escalation. The vulnerability is formally identified as CWE‑120.
Affected Systems
Apple iOS on iPhone devices, iPadOS on iPad devices, and macOS on Mac computers are impacted. Specifically, iOS 18.7.10 and 27, and iPadOS 18.7.10 and 27 are vulnerable on iPhones and iPads. On Macs, macOS Golden Gate 27, Sequoia 15.7.8 and Sonoma 14.8.8 are affected. All earlier or pre‑release versions of these operating systems remain susceptible until updated.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating that no active exploitation has been reported. The CVSS score of 5.5 reflects a moderate denial‑of‑service impact without privilege escalation. Based on the description, the likely attack vector is a malicious third‑party application that supplies crafted data to trigger the overflow. Attackers would need only to install or run such an app on an affected device.
OpenCVE Enrichment