Impact
A buffer overflow was caused by improper size validation in Apple OS components. Opening a specially crafted file can trigger the flaw, causing the targeted process to crash unexpectedly. The crash does not directly expose code execution, but it can destabilize the system and disrupt services that rely on the affected process.
Affected Systems
The vulnerability affects Apple devices running iOS earlier than version 26.7 or 27, iPadOS earlier than 26.7 or 27, macOS Golden Gate earlier than 27, macOS Sequoia earlier than 15.8, macOS Tahoe earlier than 26.7, tvOS earlier than 27, and visionOS earlier than 27. The flaw is fixed in the listed advisory versions; all earlier releases remain vulnerable until an update is applied.
Risk and Exploitability
It is not listed in CISA KEV and has an EPSS score below 1%, indicating a very low probability of exploitation. The CVSS score is 7.8, indicating high severity. The vulnerability remains local or user‑initiated, as it requires opening a maliciously crafted file. The impact is a denial of service via unexpected process termination, which can disrupt affected services but does not provide arbitrary code execution or privilege escalation.
OpenCVE Enrichment