Impact
A denial‑of‑service vulnerability arises from improper input validation. The flaw allows an attacker to craft malformed input that overwhelms the system, causing a crash or unresponsive state. This results in an availability impact while confidentiality and integrity remain unaffected. The issue is classified as moderate with a CVSS score of 6.5 and can be triggered by a remote attacker sending the malicious payload.
Affected Systems
Apple macOS is affected, including the releases Golden Gate 27, Sequoia 15.8, and Tahoe 26.7. These versions contain the fix for the input‑validation problem, and earlier releases are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 places the vulnerability in the moderate severity range. EPSS is not available, providing no current estimate of exploitation likelihood, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, most likely over the network, because the advisory notes that a remote attacker may be able to cause a denial of service. Successful exploitation requires the attacker to send malformed traffic that bypasses the component’s input validation, which then results in a service interruption until a restart or patch is applied.
OpenCVE Enrichment