Impact
The reported issue is an out‑of‑bounds write triggered during image processing. When a maliciously crafted image is handled, the write occurs beyond the intended buffer bounds, causing the target process to terminate unexpectedly. This results in a denial of service that can impact any component or third‑party application that processes images.
Affected Systems
The flaw exists in Apple devices running iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. Fixed releases include iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27; devices on earlier versions remain vulnerable.
Risk and Exploitability
EPSS data is not available and the vulnerability has not yet been listed by CISA KEV. The fault is driven by a specially crafted image file, suggesting the likely attack vector is image handling, which may be triggered locally or remotely depending on how the image is supplied. Unpatched devices are susceptible to repeated denial‑of‑service events when malicious images are processed, whereas patched systems can safely ignore or handle such images without impact.
OpenCVE Enrichment