Impact
An integrity issue in the memory management for video decoding causes applications that process maliciously crafted video files to terminate unexpectedly or corrupt process memory. The defect can be exploited by supplying a specially crafted media file to any component that decodes video, creating a local denial of service.
Affected Systems
Apple’s operating systems—including iOS, iPadOS, macOS, tvOS, and visionOS—are vulnerable. The fix is delivered in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, and visionOS 2.4. Devices running any of the listed versions of these platforms must consider the vulnerability applicable.
Risk and Exploitability
This vulnerability carries a CVSS score of 9.8, indicating critical severity. Its EPSS score is below 1 %, showing a low probability of exploitation in the wild. Although it is not listed in the CISA KEV catalog, the high impact score warrants prompt remediation. An attacker can likely trigger the flaw by delivering a malicious video file that the device processes—whether through local storage, cloud sync, or email attachment. Once the file is parsed, the resulting memory corruption or process termination can cause a local denial of service or destabilize the affected application or system.
OpenCVE Enrichment
EUVD