Impact
An attacker who can reach a device over the local network can trigger a null pointer dereference in Apple’s operating systems. The flaw results in an unexpected system crash, leading to a denial of service. Based on the description, it is inferred that the dereference occurred because an input path was not protected by validation, which aligns with CWE‑476, a null dereference due to improper input handling.
Affected Systems
Apple’s major operating systems are affected when running versions before the security updates: iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, and visionOS 2.4. Devices with earlier releases of these systems are vulnerable.
Risk and Exploitability
The CVSS score of 5.5 categorizes the vulnerability as moderate. With an EPSS score of less than 1 %, the current likelihood of exploitation is very low, and the vulnerability is not listed in CISA’s KEV catalog. However, because the attack can be performed from any device on the local network, any machine that can get within that environment represents a potential threat vector.
OpenCVE Enrichment
EUVD