Impact
An out‑of‑bounds write flaw is triggered when a disk image containing maliciously crafted data is mounted on Apple devices. The vulnerability is classified as CWE‑787, and can cause the operating system to crash or terminate unexpectedly. The flaw is mitigated by improved bounds checking in newer releases, but any older version remains vulnerable.
Affected Systems
Devices running Apple iOS, iPadOS, or macOS prior to the patch releases—iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7—are affected. All later versions contain the fix and are not impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, and the EPSS score of less than 1% shows low exploitation probability. The vulnerability is not listed in the CISA KEV catalog, and no public exploit is known. However, mounting a manipulated disk image is the required condition for exploitation, which may be possible through local or remote delivery mechanisms such as file sharing, email attachments, or device sync. Because the issue causes a denial of service, prompt remediation is advised.
OpenCVE Enrichment