Impact
An out‑of‑bounds read (CWE-125) in macOS can allow a malicious application to read kernel memory and may trigger unexpected system termination. This flaw arises from insufficient bounds checking, leading to potential data leakage and denial of service.
Affected Systems
Apple macOS operating systems are affected, including the Golden Gate, Sequoia, and Tahoe code names. The flaw is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7, so any earlier releases that have not been updated remain vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, but the EPSS score of <1% suggests a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog, indicating no publicly reported exploitation. The likely attack vector is a local malicious application, as the description suggests an app can trigger the flaw; no remote exploitation path is documented. The impact includes both confidentiality compromise through kernel memory disclosure and availability loss via unexpected crashes.
OpenCVE Enrichment