Impact
An improper input validation flaw can lead to a denial‑of‑service condition. The vulnerability is classified as resource exhaustion (CWE‑400), allowing an application to trigger a crash or unresponsive state in the operating system. The impact is the loss of availability on the affected device, potentially disrupting critical tasks or services.
Affected Systems
The flaw affects Apple’s mobile and desktop operating systems. Specifically, iOS, iPadOS, and macOS versions prior to the security releases identified (iOS 18.7, iPadOS 18.7, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26). All devices running the earlier releases are susceptible; the issue is fixed in the mentioned updates.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity. The EPSS score is below 1%, which points to a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a local application exploitation, where a malicious app or an attacker with local access can trigger the denial‑of‑service. No network‑based exploitation or elevated privileges are explicitly required in the public data.
OpenCVE Enrichment
EUVD