Impact
The vulnerability is a type confusion error that could allow a local network attacker to corrupt a process’s memory, potentially leading to arbitrary code execution or privilege escalation. The issue was made more robust with additional runtime checks, but memory corruption remains possible until the fix is applied.
Affected Systems
Apple iOS and iPadOS are affected, with the issue fixed in iOS 18.3 and iPadOS 18.3. iPadOS 17.7.4 is also patched. macOS Sequoia requires update to 15.3, macOS Sonoma to 14.7.3, tvOS to 18.3, and visionOS to 2.3. These versions must be installed for the vulnerability to be mitigated; devices running earlier releases remain vulnerable.
Risk and Exploitability
The CVSS base score of 8 signals a high severity, and the EPSS score of less than 1% indicates a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, but the potential for memory corruption means that an attacker with local network access could compromise system integrity. The attack vector is inferred as local network access since the description specifies an attacker on the local network and no remote execution path is described.
OpenCVE Enrichment
EUVD