Impact
An attacker can supply a malicious file that causes an application crash in affected Apple operating systems. The vulnerability stems from insufficient validation of file input, leading to an unexpected termination of the application. This results in a denial of service for users of the affected software and does not arbitrary code execution or privilege escalation.
Affected Systems
Apple’s iOS, iPadOS, macOS Sonoma, macOS Tahoe, and visionOS are affected. Vulnerable releases include iOS 18.7.8 and earlier, iPadOS 18.7.8 and earlier, iOS 26.4 and earlier, iPadOS 26.4 and earlier, macOS Sonoma 14.8.6 and earlier, macOS Tahoe 26.4 and earlier, and visionOS 26.4 and earlier; the releases iOS 18.7.9+, iPadOS 18.7.9+, iOS 26.5+, iPadOS 26.5+, macOS Sonoma 14.8.7+, macOS Tahoe 26.5+, and visionOS 26.5+ include the fix.
Risk and Exploitability
The CVSS score of 7.5 signals high severity, while an EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog and no public exploits are known. Attackers would need to deliver or prompt a user to open a malicious file; no network-based entry is required. The failure occurs during file parsing, causing the application to crash.
OpenCVE Enrichment