Impact
An out-of-bounds write occurs while processing a maliciously crafted image, causing memory corruption that can terminate the process handling the image. This defect does not provide evidence of code execution or information disclosure, but it can disrupt services that rely on image processing.
Affected Systems
Apple’s operating systems—iOS, iPadOS, macOS, tvOS, visionOS, and watchOS—are affected. The vulnerability is fixed in iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27. Devices running earlier versions remain at risk.
Risk and Exploitability
The EPSS score is below 1 % and the flaw is not in CISA KEV. The CVSS score of 6.5 indicates moderate severity. Attackers would need to supply a malicious image; the actual delivery method may be local or remote depending on how the application processes images, which is inferred from the described behavior. An unpatched device can suffer repeated crashes, while updated systems protect against the out-of-bounds write.
OpenCVE Enrichment