Impact
A memory corruption flaw in the audio stream processor allows a crafted audio file to trigger arbitrary code execution when processed. The defect stems from insufficient bounds checking and is classified under CWE‑119. Successful exploitation would enable an attacker to run code with the privileges of the audio processing component, potentially gaining access to the victim’s system.
Affected Systems
Apple products – iOS and iPadOS, macOS, tvOS, visionOS, and watchOS – are affected when running versions prior to iOS 18.4.1, iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1, and watchOS 11.5.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.8, indicating critical severity. An EPSS score of 2% shows it has a measurable chance of being exploited, and it is listed in the CISA KEV catalog. While the CVE description does not detail a specific entry method, the flaw is exercised by processing a malicious audio file, so local or remote delivery of such a file could lead to exploitation.
OpenCVE Enrichment
EUVD