Impact
A buffer overflow occurs in Apple’s image handling code when a maliciously crafted image is processed, because the implementation fails to perform sufficient bounds checking before copying data into a buffer. The excess data causes an application to terminate unexpectedly, which manifests as a denial of service for that application and any services that depend on it. This weakness is classified as CWE‑120, Buffer Copy without Checking Size of Destination Buffer, and the description does not indicate any potential for code execution or escalation of privileges.
Affected Systems
Apple consumers of iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are affected when they run any release earlier than version 27 of those operating systems. The fix is included in the 27th release for each platform – iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27 and watchOS 27.
Risk and Exploitability
The CVSS score of 4.3 categorizes this vulnerability as medium severity; the EPSS score of less than 1 % indicates a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker must supply a crafted image to the image processing component – either via a local file the application opens or a remote image delivered to an app – to trigger the crash. No active exploits have been reported, so the primary risk is disruption of application availability rather than compromise of confidentiality or integrity.
OpenCVE Enrichment