Impact
A buffer overflow occurs in macOS during the mounting of a maliciously crafted disk image. The vulnerability stems from insufficient bounds checking, allowing data to be written beyond a kernel buffer. The immediate consequence is corruption of kernel memory, which can cause unexpected system termination or instability. Based on the description, it is inferred that the attacker must mount a malicious disk image to trigger the overflow, as the overflow is triggered by the mounting process.
Affected Systems
Apple macOS releases older than macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 are vulnerable. Systems running the listed releases contain the fix and are no longer affected.
Risk and Exploitability
The CVSS score of 8.4 categorises the flaw as high severity, whereas the EPSS score of less than 1 % indicates a low current exploitation likelihood. The vulnerability is not listed in CISA’s KEV catalog, implying no publicly known exploits. The likely attack vector is mounting a malicious disk image; based on the description, it is inferred that the attacker must mount a maliciously crafted image for the kernel buffer overflow to occur, which can corrupt memory or terminate the system.
OpenCVE Enrichment