Impact
An out‑of‑bounds read in the disk image processing component can be triggered by a maliciously crafted disk image. The flaw results in the application unexpectedly terminating, and in some scenarios may lead to broader system instability. The weakness is a classic buffer overflow condition (CWE‑125) where improper bounds checking allows oversized input to be read beyond allocated memory boundaries.
Affected Systems
Apple macOS is affected. The issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. All earlier releases remain vulnerable as no newer patch series is listed.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact, while the EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely local or requires the user to open a malicious disk image; it is not a remote network vector. Because the flaw only causes a crash and does not grant arbitrary code execution, the severity of a successful attack is limited to denial of service rather than full system compromise.
OpenCVE Enrichment