Impact
The vulnerability is a NULL pointer dereference that can be triggered by malicious local‑network traffic, causing unexpected termination of applications. This results in a denial of service for the affected processes but does not directly compromise confidentiality or integrity. It is classified as CWE‑476.
Affected Systems
Apple iOS 18.4 and earlier, iPadOS 18.4 and iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, and watchOS 11.4. Any device running these operating systems is susceptible until the update is applied.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. With an EPSS below 1 % the likelihood of active exploitation is low. The vulnerability is not listed in the CISA KEV catalog. An attacker must have access to the same local network as the target device and be able to send crafted traffic that triggers the null dereference; no remote code execution is possible.
OpenCVE Enrichment
EUVD