Impact
The vulnerability stems from insufficient validation when parsing certain files, leading to an unexpected application termination. This results in a local denial‑of‑service condition where the affected application stops functioning without providing any data leakage or code execution capability. The weakness corresponds to CWE‑754, related to premature release or misuse of resources.
Affected Systems
Apple iOS 18.3, iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, tvOS 18.3, visionOS 2.3 and watchOS 11.3 are addressed by updated releases. Earlier versions lacking these fixes are potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity level. With an EPSS score below 1% the probability of exploitation appears very low, and the vulnerability is not catalogued in the CISA KEV list. An attacker would likely need to supply a crafted file to a target application, possibly via local access or through file sharing mechanisms; remote exploitation is not suggested by the data.
OpenCVE Enrichment
EUVD