Impact
An out-of-bounds read was identified in the file handling logic on Apple platforms. When a maliciously crafted file is opened, the operating system may read beyond the intended data boundaries, leading to either unexpected process termination or the disclosure of data residing in process memory. This flaw can compromise confidentiality and availability.
Affected Systems
Apple iOS and iPadOS releases prior to 26.7, macOS Golden Gate and earlier releases before 27, macOS Sequoia releases before 15.8, macOS Tahoe releases before 26.7, tvOS releases before 27, and visionOS releases before 27 are affected by the issue.
Risk and Exploitability
The vulnerability can be leveraged simply by opening a crafted file, making it available to users who can trigger it. An EPSS score of < 1% indicates a very low probability of exploitation, and the flaw is not listed in the CISA KEV catalog. The CVSS score of 5.4 classifies the issue as moderate severity, but the potential impact of process memory disclosure and a system crash still poses a significant threat to affected devices when untrusted files are accessed.
OpenCVE Enrichment