Impact
An out-of-bounds write issue was addressed with improved bounds checking. When a maliciously crafted 3D model is processed, memory corruption may occur (CWE-787).
Affected Systems
Apple devices, including iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27 are affected. The vulnerability is fixed in the listed versions mentioned above.
Risk and Exploitability
The CVSS score is 8.4, the EPSS score is < 1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to supply a maliciously crafted 3D file to an application or system component that accepts such files. The likelihood of exploitation remains low until an active exploit appears.
OpenCVE Enrichment