Impact
An out-of-bounds read was discovered in the font parsing component used by Apple operating systems. The vulnerability arises when a malformed font file is processed, allowing the code to read data beyond the intended buffer boundaries. This information leakage can cause the application to terminate unexpectedly. The primary impact is a denial of service—interruption of application functionality—without providing any direct gain to the attacker.
Affected Systems
Affected Apple platforms include iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27. Devices running earlier versions of these operating systems are vulnerable until an update is applied.
Risk and Exploitability
The exploit requires delivery of a crafted font file to the target. Because the failure manifests as an application crash, there is no remote code execution or privilege escalation potential; the threat is mitigated to service interruption only. No EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog, indicating limited public exploitation data. Nevertheless, organizations that deploy software capable of ingesting third‑party fonts should be mindful that attackers could target end users to force application restarts.
OpenCVE Enrichment