Impact
The flaw is an integer overflow that occurs when unvalidated input causes a wraparound of an internal counter, allowing an attacker to trigger a crash in a privileged component and thereby cause a denial of service. The vendor addressed the issue with stricter input validation and the patch is deployed in macOS Golden Gate 27, Sequoia 15.8, and Tahoe exposed to this vulnerability.
Affected Systems
Apple macOS installations running releases older than Golden Gate 27, Sequoia 15.8, or Tahoe 26.7 are affected. Users on these versions continue to be at risk because the integer overflow remains unpatched.
Risk and Exploitability
The CVSS score of 5.9 indicates Medium severity, reflecting the attack vector, privileges, and scope. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA KEV, implying requires privileged network access to deliver the overflow payload and once exploited it causes service disruption, leading to loss of availability for the affected system.
OpenCVE Enrichment