Impact
The flaw is a CWE-400 vulnerability involving inadequate memory validation that lets an application trigger faulty memory handling routines. When executed, the issue can corrupt kernel memory, leading to unexpected system termination. The impact is a loss of system availability and a compromise of kernel integrity.
Affected Systems
Apple macOS is affected. The vulnerability is resolved in macOS Sequoia 15.3, macOS Sonoma 14.7.3, and macOS Ventura 13.7.3; versions older than these releases remain vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and the EPSS score of less than 1% reflects a low likelihood of exploitation under current conditions. It is not listed in CISA KEV, suggesting no widespread known exploitation yet. The attack would most likely arise from a malicious or compromised application that runs locally on the affected Mac, providing an avenue for attackers to exploit the fault.
OpenCVE Enrichment
EUVD