Impact
A null pointer dereference was discovered in several Apple operating systems; the flaw occurs when input validation fails and a pointer is dereferenced without proper safety checks. The weakness can result in an application crash that interrupts normal operation, compromising the availability of the affected service or device. The vulnerability is formally identified as CWE-476, indicating a type safety error leading to predictable failure modes.
Affected Systems
Apple devices running iOS, iPadOS, macOS, tvOS, or visionOS are impacted. Versions prior to iOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, or visionOS 2.3 are vulnerable. The issue has been fixed by the corresponding official update releases on each platform.
Risk and Exploitability
The disclosed CVSS score of 5.7 reflects a moderate severity, while the EPSS score of less than 1% indicates a low chance of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. An attacker who can reach the device from a local network segment may trigger the dereference and cause a reboot or application termination, leading to denial of service. No additional access privileges or external networking are required for exploitation.
OpenCVE Enrichment
EUVD