Impact
A memory corruption flaw crafted audio file to trigger arbitrary code execution when processed. The defect stems from insufficient bounds checking and is classified under CWE-119. Successful exploitation would enable an attacker to run code with the privileges of the audio processing’s system.
Affected Systems
Apple products – iOS and iPadOS, macOS, tvOS, visionOS, and watchOS – are affected when running versions prior to iOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1, and watchOS 11.5.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.8, indicating critical severity, and an EPSS score of 19%, indicating a significant likelihood of exploitation. It is listed in the CISA KEV catalog. Apple reports that the issue may have been exploited in a sophisticated attack targeting specific individuals on earlier iOS releases. The description does not disclose a particular entry vector, but the flaw is exercised by processing a malicious audio file; based on the description, it is inferred that local or remote delivery of such a file could lead to exploitation.
OpenCVE Enrichment
EUVD