Impact
The vulnerability is an out-of-bounds write that allows corruption of kernel memory. A malicious application that supplies specially crafted input can write beyond the intended boundary, potentially causing a system crash or writing to kernel addresses as described. The CVE notes that this can lead to unexpected system termination or kernel memory writes, but it does not demonstrate that arbitrary code execution is possible beyond the kernel.
Affected Systems
Appleās iOS, iPadOS, macOS, visionOS, and watchOS devices are affected, specifically versions prior to iOS 18.4, iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, and watchOS 11.4. These operating systems cover mobile phones, tablets, desktops, AR/VR headsets, and smartwatches.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability is considered high severity. The EPSS score of less than 1 % indicates a low current exploitation likelihood, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local, requiring that an application be installed on the device to supply the malformed input; newer releases that include the improved input validation are no longer vulnerable.
OpenCVE Enrichment
EUVD