The issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14.8, macOS Sequoia 15.7. Processing a maliciously crafted string may lead to heap corruption.
https://support.apple.com/en-us/125112
https://support.apple.com/en-us/125111
http://seclists.org/fulldisclosure/2025/Sep/55