Impact
A remote attacker can exploit a resource exhaustion flaw caused by inadequate input validation, leading to a denial‑of‑service in macOS. The vulnerability allows an attacker to drain system resources until legitimate processes cannot run or respond. The impact is limited to affecting the availability of the affected services, without compromising confidentiality or integrity.
Affected Systems
Apple’s macOS operating system, specifically versions prior to macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. Users running any earlier releases of these code‑named macOS versions are at risk.
Risk and Exploitability
The flaw has a CVSS score of 7.5, indicating a high severity. The EPSS score is very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to supply malformed or excessive input to trigger the resource exhaustion, so the attack vector is likely remote via network or local user input, depending on the vulnerable component. Prevention requires applying the patch delivered in the aforementioned macOS updates.
OpenCVE Enrichment