Impact
A buffer overflow occurs when the system processes a maliciously crafted disk image during the mounting operation. The flaw arises from insufficient bounds checking, allowing an out‑of‑bounds write to kernel memory. This can lead to unexpected system termination or corrupt kernel memory.
Affected Systems
Apple macOS operating systems in the Golden Gate, Sequoia, and Tahoe series are affected. The flaw is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. Users running earlier releases of any of these branches are susceptible until they apply a later update.
Risk and Exploitability
The CVSS score of 8.8 classifies the issue as high severity, indicating significant impact on confidentiality, integrity, and availability. The EPSS score of < 1 % suggests that exploitation is unlikely but still possible, and the flaw is not listed in the CISA KEV catalog. Attackers likely need to supply a crafted disk image that is mounted on the target system, making local or privileged exploitation most probable. Administrators should consider the vulnerability critical and apply the patch promptly.
OpenCVE Enrichment