Impact
The vulnerability arises from improper memory handling during file parsing, which can trigger a buffer overflow and cause the application to terminate unexpectedly. An attacker may supply a crafted file to induce this crash. The primary effect is a denial of service, disrupting user operations and potentially leading to loss of service availability. The weakness is classified as CWE-119.
Affected Systems
Affected Apple operating systems include iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, and watchOS 11.6. These versions contain the vulnerable memory handling code.
Risk and Exploitability
With a CVSS score of 9.8, the flaw is considered highly severe. The EPSS score of less than 1% indicates a low probability of exploitation at the present time, and the vulnerability is not listed in the CISA KEV catalog. Exploitation likely requires an attacker to provide a malicious file that the affected system parses locally, leading to a crash. Monitoring for repeated crash events and ensuring that files come from trusted sources can mitigate risk until updates are applied.
OpenCVE Enrichment
EUVD