Impact
A memory handling flaw (CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer) in Apple's operating systems can be triggered by an application to cause the system to terminate unexpectedly. The issue was fixed in later OS releases via improved memory handling, indicating that improper buffer usage in older OS versions may lead to system instability. An attacker could trigger a crash that affects device availability, resulting in loss of service until a restart or a new update is installed.
Affected Systems
Apple iOS and iPadOS versions older than 18.7.2 and 26.1, macOS Sequoia older than 15.7.2, macOS Sonoma older than 14.8.2, macOS Tahoe older than 26.1, tvOS older than 26.1, visionOS older than 26.1, and watchOS older than 26.1 are affected. Devices running any of these operating system versions are susceptible until updated with releases that contain the memory handling fix.
Risk and Exploitability
The CVSS score of 5.5 suggests moderate severity, while the EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. The flaw is not listed in CISA's KEV catalog. An attacker can exploit the issue by installing or running a rogue application on the device, which can trigger the memory handling problem and cause a crash. The attack vector is inferred to be local via a malicious app, as the description states an app may be able to cause unexpected termination.
OpenCVE Enrichment