Impact
An out‑of‑bounds read occurs when a macOS system processes a maliciously crafted file because the bounds checking performed on the input buffer was insufficient. The flaw, classified as CWE‑125, allows the application to read memory beyond the intended buffer, which can lead to the accidental disclosure of process memory or cause the application to terminate unexpectedly.
Affected Systems
The vulnerability affects Apple macOS versions older than macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. Users running any earlier releases remain susceptible to the out‑of‑bounds read during the processing of files containing crafted payloads.
Risk and Exploitability
The CVSS score of 8.1 marks this as a high‑severity issue, while the EPSS score of less than 1% suggests a low probability of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating no large‑scale exploitation has been documented. The attack vector is likely a file that an affected application processes, where an attacker could supply a crafted file to trigger the read past the buffer and potentially leak sensitive data or cause a crash. The risk can be mitigated by keeping the operating system up‑to‑date, disabling or isolating untrusted file processing, and ensuring system integrity controls such as Gatekeeper remain enabled.
OpenCVE Enrichment