Impact
An out‑of‑bounds read occurs when software processes a maliciously crafted font, potentially exposing the contents of process memory. The vulnerability originates from insufficient bounds checking and allows an attacker to read memory beyond intended limits, thereby disclosing sensitive data. This weakness is formally classified as an out‑of‑bounds read flaw.
Affected Systems
Apple devices running any of the following operating systems prior to version 27 are affected: iOS, iPadOS, macOS Golden Gate, tvOS, visionOS, and watchOS. All mentioned platforms received a patch in their 27th major release, which introduces stricter bounds verification to eliminate the read fault.
Risk and Exploitability
Because the issue requires parsing a font file, the most likely attack vector is local file exploitation, which could occur when a user opens a malicious document or installs a compromised application that injects a crafted font. The severity of the memory disclosure can lead to exposure of personal or system data, but the available metrics vulnerability is not listed in CISA’s KEV catalog. Attackers would still need to supply the offending font, meaning the risk remains moderate but significant for any device that processes untrusted fonts.
OpenCVE Enrichment