Impact
A heap buffer overflow in Apple’s iOS, iPadOS, and macOS operating systems occurs during the bounds‑checked processing of volume mount operations. The flaw allows malicious data from a volume to overflow a heap buffer, corrupting memory and causing the system to crash unexpectedly, resulting in an unsolicited system termination that takes down the kernel or related processes.
Affected Systems
The vulnerability affects Apple iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. Devices running any of these operating system releases are susceptible when a malicious or tampered volume is mounted.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1 % suggests a low probability of widespread exploitation at the time this analysis was performed. The vulnerability is not listed in CISA’s KEV catalog. Attacking requires access to a volume that can be mounted locally; no publicly described exploit code is present in the available data, so remediation is strongly recommended.
OpenCVE Enrichment