Impact
An out-of-bounds read vulnerability (CWE-125) is triggered when a maliciously crafted font is processed by the operating system. This flaw allows an attacker to read portions of a process’s memory that should be inaccessible, potentially leaking sensitive data such as passwords, cryptographic keys, or other confidential information. The weakness stems from insufficient bounds checking during font parsing, which can lead to accidental disclosure of memory contents.
Affected Systems
Apple devices running iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, or watchOS 27 are not affected. These versions contain the patch that tightens input validation to prevent the out-of-bounds read. All earlier releases of each platform remain vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while an EPSS score of less than 1 % signals a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, further reducing the likelihood of widespread attacks. The most likely attack path involves delivering a malicious font through a compromised or malicious application, or via a user-initiated font installation. Exploitation would grant an attacker read access to the memory of the process rendering the font, compromising confidentiality for the affected user but not enabling arbitrary code execution. The limited scope and low exploitation likelihood suggest monitoring and prompt patching rather than immediate emergency measures.
OpenCVE Enrichment