Impact
This vulnerability stems from improper memory handling that can trigger a buffer overflow (CWE‑120) in several Apple operating systems. The flaw can cause the operating system to crash or become unresponsive, resulting in a denial of service for legitimate users. The detailed mechanism involves corrupting memory during routine operations, but the CVE does not provide explicit information about the exact trigger data.
Affected Systems
Apple operating systems affected include iOS, iPadOS, macOS, tvOS, and visionOS. The issue has been fixed in iOS 18.3, iPadOS 18.3 and 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, and visionOS 2.3. Devices running older releases remain vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. The EPSS score of less than 1% suggests a very low probability of exploitation at the time of the analysis. The vulnerability is not listed in the CISA KEV catalog, meaning there are no known large-scale attacks. The attack vector is inferred to be local network connectivity, so an adversary would need physical or network access to the target device to exploit the flaw. The overall risk is moderate but largely limited to environments where local network access is possible.
OpenCVE Enrichment
EUVD