Impact
The vulnerability is an out-of-bounds write that occurs when processing a deliberately malformed USD file. The flaw allows malicious data to overwrite memory beyond the intended buffer, leading to unexpected application termination. The weakness is classified as CWE‑787. Because the damage is limited to application instability, the primary impact is a denial of service rather than full system compromise.
Affected Systems
Affected Apple platforms include iOS, iPadOS, macOS, and visionOS. The issue has been fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sonoma 14.8.4, macOS Tahoe 26.3 and visionOS 26.3. Any earlier releases of these operating systems are potentially vulnerable until the corresponding update is applied.
Risk and Exploitability
The vulnerability scores a CVSS of 8.8, indicating a high severity. Its EPSS score is below 1 %, suggesting that exploitation is currently unlikely to be widespread. The flaw is not listed in the CISA KEV catalog. Attackers would need to supply a crafted USD file to the vulnerable application, which likely requires local or user‑initiated file access; there is no evidence of remote exploitation paths.
OpenCVE Enrichment