Impact
An out-of-bounds write occurs when the system processes a maliciously crafted image due to insufficient bounds checking. The flaw can trigger an unexpected termination of the receiving application, disrupting user experience and service availability. No evidence in the data indicates that the memory corruption can be leveraged for code execution or privilege escalation, so the primary consequence remains a denial of service.
Affected Systems
Apple iOS versions earlier than 26.7, iPadOS versions earlier than 26.7, and macOS Golden Gate releases prior to 27 are affected. The issue is fixed in iOS 26.7, iPadOS 26.7, and macOS Golden Gate 27.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, while the EPSS score of less than 1 percent suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, meaning no known active exploitation. The likely attack vector is the delivery of a malicious image to a vulnerable application, which may cause the application to crash.
OpenCVE Enrichment