Impact
The vulnerability involves an out‑of‑bounds write in several sandboxed processes, allowing a process to write memory beyond the intended bounds. This flaw can potentially enable a sandboxed application to bypass the sandbox restrictions that are meant to limit its access to system resources, thereby exposing the integrity and stability of the affected system to risk.
Affected Systems
Affected Apple operating systems include iOS, iPadOS, macOS (Golden Gate, Sequoia, Tahoe), visionOS, and watchOS. Versions before iOS 26.7, iPadOS 26.7, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, and watchOS 27 are vulnerable and should be upgraded to the patched releases.
Risk and Exploitability
The CVSS score of 5.2 indicates moderate severity, while the EPSS score is <1% and the vulnerability is not listed in the KEV catalog, suggesting that widespread exploitation is unlikely. Based on the description, it is inferred that an attacker would need to exploit a local sandboxed process that triggers the memory overwrite in order to circumvent sandbox restrictions. The potential impact is limited to the capabilities of the sandboxed process; explicit elevation of privileges beyond the sandbox is not confirmed by the available data.
OpenCVE Enrichment