Impact
An assertion failure reachable through malformed input was discovered in certain Apple iOS and iPadOS versions. The flaw originates from insufficient input validation that allows an attacker to trigger a defensive assertion, causing the system to crash and halt normal operation. The result is a denial‑of‑service, preventing legitimate use of the affected device until it is restarted.
Affected Systems
The vulnerability impacts all Apple iOS and iPadOS releases older than 18.7.10. The fix was incorporated in iOS 18.7.10 and iPadOS 18.7.10, which address the input‑validation issue.
Risk and Exploitability
Based on the description, it is inferred that an attacker must be in a privileged position on the same network as the device to send specially crafted input. The EPSS score is not available and the flaw is not listed in CISA KEV, suggesting that there are no known public exploits, but the limited attack surface still warrants remediation. A crash can disrupt device availability until a reboot occurs.
OpenCVE Enrichment