Impact
A heap buffer overflow exists in several Apple operating systems that can be triggered when a maliciously crafted file is processed. The overflow is fixed by improved bounds checking and, if triggered, may lead to unexpected application termination, effectively denying service for the affected app. The vulnerability falls under the category of a heap-based buffer overflow.
Affected Systems
Apple iOS (pre‑26.7), iPadOS (pre‑26.7), macOS Golden Gate (pre‑27), visionOS (pre‑27), and watchOS (pre‑27) are all impacted. Version numbers that include the mitigation are iOS 26.7, iPadOS 26.7, macOS Golden Gate 27, visionOS 27, and watchOS 27.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog. Because the flaw is limited to a heap buffer overflow triggered by a malicious file, the likely attack vector is a local or privilege‑escalated scenario where an attacker can supply such a file. Without an exploit available in the wild yet, the risk remains moderate, but the impact of an exploit would be a rapid crash of the targeted application, potentially affecting availability for users. Apple's public advisories recommend applying the listed OS updates to eliminate the flaw.
OpenCVE Enrichment