Impact
Apple’s operating systems contain a flaw where insufficient validation during internal operations can allow a remote attacker to trigger a crash that terminates the system unexpectedly. The weakness, identified as CWE‑754, does not require authentication and can lead to a denial of service by causing the entire OS to exit or reboot abruptly. The impact is system instability and loss of service availability, potentially exposing users to repeated disruptions.
Affected Systems
vulnerable versions of Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS fall below the following releases: iOS 18.5, iPadOS 18.5 and 17.7.9, macOS Sequoia 15.5 and macOS Ventura 13.7.7, tvOS 18.5, visionOS 2.5, and watchOS 11.5. All earlier builds of each platform are considered affected.
Risk and Exploitability
The CVSS score of 7.5 indicates a serious vulnerability that could allow remote exploitation. The EPSS score is under 1%, suggesting a low but non‑zero likelihood of exploitation in the near term, and the issue has not yet been catalogued by CISA’s KEV program. The most probable attack vector is remote, though the specific trigger mechanism is not detailed in the advisory.
OpenCVE Enrichment
EUVD