Impact
The vulnerability is an input validation flaw that lets a remote user send specially crafted data to trigger a crash in Apple platform software. The result is a denial‑of‑service, affecting the availability of the device or service. There is no evidence of confidentiality or integrity compromise in the description.
Affected Systems
Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS could be affected. Versions older than iOS 18.4, iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, and watchOS 11.4 are vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The EPSS score of less than 1% suggests that the likelihood of real-world exploitation is currently low. The vulnerability is not included in CISA’s KEV catalog. The attack vector is remote, likely via a network or over‑the‑air channel, where an attacker can transmit malformed packets or requests to cause the device to crash.
OpenCVE Enrichment
EUVD