Impact
The vulnerability stems from insufficient state management within Apple’s iOS and iPadOS platforms, allowing remote content to be fetched even when the 'Load Remote Images' preference is disabled. This defect can lead to unintended data transfer and possible exposure of confidential information or malicious payloads to the device, consistent with the identified weakness in CWE‑359.
Affected Systems
Affected products are iOS and iPadOS on all Apple devices. The issue is mitigated in iOS 18.6 and iPadOS 18.6 as well as iPadOS 17.7.9. No earlier versions are listed as patched, so devices running older releases remain vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score of less than 1% suggests low likelihood of exploitation in the near term. The vulnerability is not present in the CISA KEV catalog, implying no known widespread exploitation. Attackers could trigger the flaw by presenting or navigating to a web page that contains remote images; the mechanism requires user interaction or an application that loads such content, making it a local, user‑initiated attack vector.
OpenCVE Enrichment
EUVD