Impact
An out-of-bounds write flaw in Apple's 3D model processing code permits a malicious model to corrupt memory locations. The vulnerability arises from insufficient bounds verification, which may allow an attacker to overwrite adjacent memory structures. If exploited, an attacker could potentially execute arbitrary code or crash the application, resulting in loss of data or functionality.
Affected Systems
Affected products include Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. Versions prior to iOS OS 26.7, iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27 remain vulnerable. System administrators should verify the operating system and upgrade if still running an older version.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity, while the EPSS score of <1% suggests a low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires delivering a maliciously crafted 3D model to the device for processing by the native viewer or a web integration. The likely attack vector is local or remote, depending on whether sourced 3D content. Given the memory corruption risk, an attacker could achieve arbitrary code execution or a denial of service.
OpenCVE Enrichment