Impact
The vulnerability arises from an improper release of a privileged resource, identified as CWE-416. An attacker on the same local network can exploit the flaw to cause the targeted application to terminate unexpectedly, leading to a denial of service. The flaw does not enable code execution or data disclosure.
Affected Systems
Apple devices running iOS 18.4, iPadOS 18.4 or iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, and visionOS 2.4 are impacted. Earlier releases of these operating systems are not affected.
Risk and Exploitability
The CVSS score of 5.7 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local network access and the attacker must trigger the improper release within the affected application; there is no remote code execution or privilege escalation possible.
OpenCVE Enrichment
EUVD