Impact
An integer overflow flaw was present in several Apple operating systems; the issue was addressed with improved input validation. The vulnerability allows a remote attacker to trigger the overflow, potentially causing a memory leak and exposing sensitive data.
Affected Systems
Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are affected. The flaw has been fixed in iOS 18.5, iPadOS 18.5 and iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, and watchOS 11.5.
Risk and Exploitability
The vulnerability has a CVSS score of 7.5, indicating high severity. Its EPSS score is reported as < 1%, suggesting a low probability of exploitation in the wild, and it is not listed in CISA’s KEV catalog. A remote attacker is the likely vector, as the CVE description explicitly states that a remote attacker may be able to leak memory.
OpenCVE Enrichment
EUVD