Impact
The vulnerability arises from insufficient bounds checking in the handling of Human Interface Device (HID) input, a classic buffer overflow (CWE-119). A malicious HID device can exploit this flaw, causing the affected process to crash unexpectedly. The result is a denial of service condition that can interrupt service and degrade user experience.
Affected Systems
Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are affected. The specific versions impacted by this flaw include iOS 18.7.5, iPadOS 18.7.5, iOS 26.2, iPadOS 26.2, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, and watchOS 26.2.
Risk and Exploitability
The CVSS score of 5.7 indicates a moderate severity, and the EPSS score of less than 1% suggests a low but non‑zero likelihood of exploitation. This vulnerability is not listed in the CISA KEV catalog. The attack vector is likely physical; an attacker must supply a malicious HID device to the target system. Once the device is connected, the flaw will trigger an immediate crash of the victim process, providing potential for denial of service in the affected Apple operating systems.
OpenCVE Enrichment