Impact
An out‑of‑bounds write was discovered in Apple’s graphics stack, addressed by improved bounds checking. Crafting a malicious 3‑D scene that exceeds expected limits can trigger the out‑of‑bounds write and cause the rendering process to terminate unexpectedly. The resulting denial of service can affect user experience and application availability, though no evidence of code execution or data leakage is present in the description.
Affected Systems
Vulnerable Apple products include iOS and iPadOS, macOS (Golden Gate 27, Sequoia 15.8, Tahoe 26.7), tvOS 27, visionOS 27, and watchOS 27. The issue was fixed starting with iOS 26.7 / iPadOS 26.7, iOS 27 / iPadOS 27, and corresponding macOS, tvOS, visionOS, and watchOS releases.
Risk and Exploitability
Severity metrics are not provided; EPSS is missing and the vulnerability is not listed in CISA’s KEV catalog. The attack likely requires an attacker to supply or influence a 3‑D scene that is processed by the device, so an active component or user‑driven input is necessary. While the absence of exploit data suggests low to moderate risk, the impact is a denial of service that can disrupt device usability.
OpenCVE Enrichment