Impact
An out‑of‑bounds read in font parsing allows a maliciously crafted font to read beyond the intended buffer, exposing content from the process memory. This flaw is formally classified as CWE‑125. If exploited, the vulnerability could lead to disclosure of sensitive data stored in memory, jeopardizing confidentiality of user or system information.
Affected Systems
Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS devices running any major release earlier than version 27 are impacted, as the code lacks the bounds verification introduced in the 27th major release.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, and the EPSS score of less than 1 % signifies that widespread exploitation is unlikely. The vulnerability is not listed in CISA’s KEV catalog. The most probable attack vector is a local file exploitation where an attacker supplies a malicious font through a document, application, or browser, as inferred from the flaw description. Successful exploitation could expose user or system data, presenting a moderate risk to affected systems that accept untrusted font files.
OpenCVE Enrichment