Impact
An improper memory handling flaw in the 3D model rendering pipeline causes a buffer assignment error (CWE-120) when a crafted 3D file is parsed. The resulting memory corruption can lead to application crashes and, depending on the execution context, may provide a vector for arbitrary code execution. The vulnerability is triggered only when the system processes a maliciously crafted 3D model.
Affected Systems
Apple iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27 are affected. All earlier releases that have not applied the 26.7/27 updates remain vulnerable.
Risk and Exploitability
The CVSS score of 7.3 indicates high severity, while the EPSS score of <1% shows a very low expected exploitation probability. The issue is not listed in the CISA KEV catalog. Exploitation would require an attacker to deliver or load a crafted 3D model in any application or system component that parses such content, making the risk primarily local or dependent on how 3D files are obtained.
OpenCVE Enrichment