Impact
The reported issue is an out-of-bounds read that caused unexpected system termination. The flaw was mitigated with enhanced bounds checking. While the vulnerability does not appear to expose data or enable privilege escalation, it leads to a denial-of-service by crashing the operating system.
Affected Systems
Affected platforms are Apple macOS versions prior to the patch releases documented by Apple. Specifically, all macOS Ventura builds earlier than 13.7.7, all macOS Sonoma builds earlier than 14.7.7, and all macOS Sequoia builds earlier than 15.6 are impacted. Applications running on those systems could trigger the crash if the out-of-bounds condition is met.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score is under 1 %, implying that the likelihood of exploitation is low. The vulnerability is not catalogued in the CISA KEV database. Because the flaw appears to be exercised through an improper memory read, the most likely scenario is a malicious application or specially crafted input that triggers the defect; the consequence is purely a denial-of-service via system termination.
OpenCVE Enrichment
EUVD