Impact
The vulnerability arises from improper memory handling that allows an application to trigger unexpected system termination, which results in a denial of service. This weakness falls under CWE-400: Uncontrolled Resource Consumption, meaning that the system’s resources can be mismanaged to cause a crash.
Affected Systems
Apple macOS versions prior to Sequoia 15.4 are affected. The issue is fixed in macOS Sequoia 15.4, so any system running an earlier release is at risk.
Risk and Exploitability
With a CVSS score of 9.8 the severity is critical, yet the EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local, as the exploit requires launching or interacting with a malicious application that triggers the memory handling fault. Consequences include loss of availability, potential exposure of the crash state, and interruption of business operations.
OpenCVE Enrichment
EUVD