Impact
A remote attacker may trigger a service crash by sending input that is not properly validated. The CVE description does not detail the precise form of the input, but it is inferred the service reboot or become unusable, compromising device availability.
Affected Systems
All Apple iOS and iPadOS devices running a version earlier than 18.7.10 are affected. The issue is resolved in iOS 18.7.10 and iPadOS 18.7.10, so any device still on an earlier release is at risk.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. With an EPSS score of < 1% and the likelihood of exploitation is very low, although the potential impact on device availability is significant. It is inferred that the vulnerability can be triggered remotely, though the specific attack vector is not disclosed; remote access to the device appears sufficient to exploit the flaw.
OpenCVE Enrichment