Impact
A memory handling flaw in Apple operating systems can be exploited by an application to provoke an unexpected system termination. The vulnerability creates a state where the operating system crashes, leading to a denial of service. The weakness involves improper cleanup or validation of system memory during application execution.
Affected Systems
The flaw affects Apple iOS 18.3, iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, and watchOS 11.3. All versions of iOS, iPadOS, macOS, tvOS, visionOS, and watchOS released before these patches are potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog, further indicating limited exploitation activity so far. The likely attack vector is an application installed on the device, which may be malicious or poorly written, and can trigger the crash without requiring elevated privileges. Once exploited, the affected system becomes unavailable until restarted, impacting user productivity and potentially disrupting critical services.
OpenCVE Enrichment
EUVD