The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. Processing a maliciously crafted string may lead to heap corruption.
https://support.apple.com/en-us/125112
https://support.apple.com/en-us/125111
https://support.apple.com/en-us/125110
http://seclists.org/fulldisclosure/2025/Sep/55