This issue was addressed by removing the vulnerable code. This issue is fixed in visionOS 26, tvOS 26, iOS 26 and iPadOS 26, watchOS 26. An input validation issue was addressed.
https://support.apple.com/en-us/125116
https://support.apple.com/en-us/125115
https://support.apple.com/en-us/125114
https://support.apple.com/en-us/125108
http://seclists.org/fulldisclosure/2025/Sep/58
http://seclists.org/fulldisclosure/2025/Sep/57
http://seclists.org/fulldisclosure/2025/Sep/56