Impact
A buffer overflow in the macOS kernel arises from insufficient size validation, which can lead to unexpected system termination or kernel memory corruption. The vulnerability is a classic buffer overflow where boundary checks around a memory buffer are missing. Based on the description, it is inferred that an attacker with local access could trigger this overflow to destabilize the system.
Affected Systems
Apple macOS systems of versions earlier than macOS Golden Gate 27 are affected; the fix is included in macOS Golden Gate 27 and later releases.
Risk and Exploitability
The attack vector is likely local; a user with local privileges could exploit the overflow. The EPSS score is reported as less than 1%, indicating a low but non‑zero probability of exploitation. The CVSS score of 9.8 indicates a critical severity. The vulnerability is not listed in the CISA KeV catalog and is fixed in macOS Golden Gate 27 or later releases.
OpenCVE Enrichment