Impact
The issue originates from a memory handling flaw in macOS that allows an application to read or write outside the intended memory region, leading to kernel memory corruption. This corruption can trigger an unexpected system termination or crash. The weakness is reflected in CWE-119, which covers improper restriction of operations within the bounds of a memory buffer. The description does not state that the flaw can be leveraged for remote code execution or privilege escalation, so the impact is limited to loss of system availability.
Affected Systems
Apple macOS releases older than macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 are vulnerable. The issue affects all installations of those operating systems that have not yet applied the patch, regardless of hardware configuration.
Risk and Exploitability
The CVSS score of 6.6 rates the vulnerability as moderate severity. The EPSS score of less than 1 percent indicates a very low probability of exploitation in the near term. The vulnerability does not appear in the CISA KEV catalog and no public exploits are known. The attack vector is not explicitly described, but the description indicates that an application running on the system may trigger the memory flaw. If successfully exploited, kernel memory corruption could lead to a system crash. The low exploitation probability and lack of a clear remote attack surface reduce urgency, but enterprises running affected macOS versions should apply the patch promptly.
OpenCVE Enrichment