Impact
Parsing a file may trigger an unexpected termination of the application. The weakness involves improper resource handling, as indicated by CWE‑770, and can lead to an abrupt service interruption for the affected app, potentially allowing denial of service to legitimate users.
Affected Systems
Apple iOS, iPadOS, macOS, tvOS, and visionOS are impacted. The vulnerability has been fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.3, and visionOS 2.3.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation. It is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is local file ingestion by a target application; an attacker would need to supply a malicious file to trigger the crash.
OpenCVE Enrichment
EUVD