Impact
An uncontrolled format string issue exists that can allow an affected application to cause a denial-of-service by crashing or destabilizing the system. The vulnerability arises from improper input validation of format strings and is fixed by the vendor with an updated implementation.
Affected Systems
Apple macOS systems running versions older than macOS Sequoia 15.4, macOS Sonoma 14.7.5, or macOS Ventura 13.7.5 are affected. Upgrading to these or newer releases eliminates the flaw.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score of less than 1% suggests a very low probability of exploitation at the time of analysis, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is local, with the compromised application exploiting the format string to trigger a crash, but no remote code execution or elevation of privilege is disclosed.
OpenCVE Enrichment
EUVD