Impact
An integer overflow flaw was identified in Apple macOS. The vulnerability arises from insufficient input validation, allowing an attacker to provide a large numeric value that overflows an internal counter and results in the operating system terminating unexpectedly. This defect is tied to integer overflows (CWE‑190). The CVE description does not explicitly state that the overflow can result in arbitrary code execution or privilege escalation; however, it can cause a system crash, leading to a denial of service.
Affected Systems
Apple macOS versions older than macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 are affected. The operating system has patched the flaw in those should check their installed macOS version and upgrade if it precedes these fixed releases.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and the EPSS score of less than 1% reflects a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The exploitation involves supplying a malicious input that overloads the integer handling routine; however, the description does not specify whether this can be performed locally or remotely, so the attack vector is uncertain.
OpenCVE Enrichment