Impact
The vulnerability arises from an uninitialized memory region that is used during image processing. When a crafted image is processed, data that was never properly initialized can be read from the process’s memory, releasing sensitive information. This is a classic instance of uninitialized variable usage (CWE-457). The CVSS score of 4.3 indicates a low severity rating.
Affected Systems
Apple devices running affected operating system releases: iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, which signifies a low probability of widespread exploitation. Based on the description, it is inferred that an attacker could deliver a malicious image—such as by prompting a user to open a file locally or via remote image handling—to trigger the memory disclosure. The resulting leak could expose data residing in the process’s address space. Although exploitation has not been publicly documented, the confidentiality impact recommends timely patching.
OpenCVE Enrichment