Impact
An out‑of‑bounds write vulnerability has been identified in several Apple operating systems. The flaw arises from insufficient input validation and is classified as a buffer overflow (CWE-787) and an unchecked resource handling issue (CWE-757). If exploited, an attacker can corrupt kernel memory, which may lead to unexpected system termination or higher‑privilege escalation. The severity, as reflected by a CVSS score of 9.1, indicates a critical security concern.
Affected Systems
Apple iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, and visionOS 2.3 are affected by the flaw.
Risk and Exploitability
The EPSS score (< 1%) indicates a very low present‑day exploitation probability, and the vulnerability is not yet listed in CISA’s KEV catalog. Nonetheless, the high CVSS score and the nature of the flaw – a kernel‑level out‑of‑bounds write – mean that any successful exploitation could have catastrophic consequences. The attack vector is not explicitly documented in the provided data, but the description implies that an attacker could trigger the flaw through malformed input to an OS component, potentially requiring local or privileged access to deliver the exploit.
OpenCVE Enrichment
EUVD