Impact
An integer overflow was discovered in the processing of 3D models on Apple devices, leading to memory corruption. This vulnerability arises from improper input validation when parsing maliciously crafted model files, potentially allowing an attacker to overwrite arbitrary memory locations or achieve unintended control flow. The weakness corresponds to known classes of buffer overreach vulnerabilities.
Affected Systems
The flaw affects several Apple operating systems. Fixed versions include iOS 26.OS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27. Devices running earlier releases of these platforms are at risk.
Risk and Exploitability
The EPSS score is < 1%, and the vulnerability is not listed in CISA’s KEV catalog, implying that public exploitation data is inferred to involve delivery of a malicious 3D model to a target device, likely via a compromised or malicious application. While the observable severity is high due to potential memory corruption, the absolute risk depends on adoption of older platform versions and the presence of third‑party applications that load such content.
OpenCVE Enrichment