Impact
The vulnerability is caused by improper memory handling that allows an application to write to kernel memory or cause unexpected system termination. This flaw is identified as CWE‑787, a buffer or heap overflow that permits arbitrary memory writes. The impact is severe because a corrupted kernel memory state can destabilize the entire operating system.
Affected Systems
All Apple iPadOS releases prior to 17.7.4 and all macOS releases prior to Sequoia 15.3 or Sonoma 14.7.3 are affected. Any device running those versions could be vulnerable to this flaw.
Risk and Exploitability
With a CVSS score of 9.8 and an EPSS score of 27%, the vulnerability is highly critical and likely to be exploited locally. It is not yet listed in the CISA KEV catalog. The CVE description indicates that a malicious or compromised application can trigger the kernel memory write or cause system termination, but it does not specify whether elevated privileges are required. The attack surface is local to the device, accessed via software running on the target system.
OpenCVE Enrichment
EUVD