Impact
An out‑of‑bounds read was identified in the file handling logic on Apple platforms. When a maliciously crafted file is opened, the operating system may read beyond the intended data boundaries, leading to either an unexpected termination of the process or the disclosure of data residing in process memory. This flaw can compromise the confidentiality and availability of the affected system.
Affected Systems
Apple iOS 26.7, 27 and iPadOS 26.7, 27 are affected, as are macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, and visionOS 27. The issue is confined to these operating system releases and is not present in earlier versions. The vulnerability stems from insufficient input validation when parsing certain file types.
Risk and Exploitability
The vulnerability can be leveraged simply by opening a crafted file, making it available to users who can trigger it. No EPSS score is reported and the flaw is not listed in the CISA KEV catalog, yet the potential impact of process memory disclosure and a system crash suggests a high severity. The lack of a CVSS rating makes precise assessment difficult, but the flaw poses a serious threat to affected devices where untrusted files may be accessed.
OpenCVE Enrichment