Impact
An out‑of‑bounds write bug (CWE‑787) was addressed with improved bounds checking; processing a maliciously crafted file may lead to unexpected app termination.
Affected Systems
Apple operating systems including iOS, iPadOS, macOS (Golden Gate, Sequoia, Tahoe), tvOS, visionOS, and watchOS are affected. The vulnerability is mitigated in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, vision 27, and watchOS 27.
Risk and Exploitability
The CVSS score is 7.8 and the EPSS score is less than 1%, indicating a high severity but low current exploitation probability. Based on the description, the vulnerability does not provide a direct code execution path; instead, a maliciously crafted file may trigger application crashes when opened, representing a denial‑of‑service risk that requires user interaction to trigger. Additionally, the vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment