Impact
The vulnerability is an out‑of‑bounds read that can occur when the system mounts an exFAT volume containing specially crafted data. The failure in input validation allows the kernel to read memory outside of the intended buffer, potentially exposing kernel memory contents or causing the system to terminate unexpectedly. The weakness is a classic buffer over‑read (CWE‑126).
Affected Systems
Apple macOS users running versions prior to macOS Golden Gate 27 are affected. The issue was fixed in macOS Golden Gate 27, so any older macOS release carries the risk.
Risk and Exploitability
EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, which suggests there is no current evidence of exploitation at the time of this assessment. The likely attack vector is local, requiring a user or process to mount a malicious exFAT volume. While the CVSS score is not provided, the potential for kernel memory disclosure or an unexpected system crash indicates a serious impact for affected systems.
OpenCVE Enrichment