Impact
A memory corruption flaw in the audio stream processor allows a crafted audio file to trigger arbitrary code execution when processed. The defect stems from insufficient bounds checking and is classified under CWE-119. Successful exploitation would enable an attacker to run code with the privileges of the audio processing component, potentially gaining access to the victim’s system.
Affected Systems
Apple products – iOS and iPadOS, macOS, tvOS, visionOS, and watchOS – are affected when running versions prior to iOS 18.4.1, iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1, and watchOS 11.5.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.8, indicating critical severity, and an EPSS score of 20%, indicating a significant likelihood of exploitation. It is listed in the CISA KEV catalog. Apple reports that the issue may have been exploited in a sophisticated attack targeting specific individuals on earlier iOS releases. The description does not disclose a particular entry vector, but the flaw is exercised by processing a malicious audio file; based on the description, it is inferred that local or remote delivery of such a file could lead to exploitation.
OpenCVE Enrichment
EUVD