Impact
The vulnerability is a use‑after‑free that can cause an application to terminate unexpectedly. An attacker exploiting this flaw can force the target process to crash, resulting in a denial of service that may impact user experience and system stability. This weakness is classified as CWE‑416, reflecting a vulnerable release or deletion of memory that continues to be referenced.
Affected Systems
Apple devices running iPadOS or macOS versions that have not applied the latest security update are affected. The patch was released for iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, and macOS Ventura 13.7.7. All prior releases of these operating systems remain vulnerable.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical risk, but the EPSS score of less than 1% suggests that exploitation in the wild is unlikely at present. The vulnerability is not listed in the CISA KEV catalog, which further reduces the perceived threat level. Based on the description, it is inferred that the attack vector would require an attacker to trigger the use‑after‑free through a malicious application or otherwise deliver code that takes advantage of the freed memory. No publicly available exploits have yet been reported.
OpenCVE Enrichment
EUVD