Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows remote user-assisted attackers to execute arbitrary code via a crafted photocast with format string specifiers in the title of an RSS iPhoto feed.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.341
EPSS Ranking 96.8%