Impact
Processing a maliciously crafted asset catalog can lead to memory disclosure due to a bounds‑checking failure (CWE‑125). The updated advisory notes that Apple has addressed this with improved memory handling, and the fix is in iOS 18.7.10, iPadOS 18.7.10, iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.8 and macOS Sonoma 14.8.8. The details of the vulnerability and its impact have been updated, but the core risk remains a process memory exposure when handling untrusted asset catalogs.
Affected Systems
Apple iOS, iPadOS and macOS products are affected, specifically versions prior to iOS 18.7.10, iPadOS 18.7.10, macOS Sequoia 15.7.8 and macOS Sonoma 14.8.8. The vulnerable code path processes asset catalogs, which are used to bundle resources for applications. Users running these operating system releases are potentially exposed to memory disclosure if they process maliciously crafted catalogs.
Risk and Exploitability
With a CVSS score of 5.5, the vulnerability represents moderate severity. The EPSS score is below 1%, indicating a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is delivery of a malicious asset catalog to macOS or a privileged application; exploitation requires the ability to supply a crafted catalog to the vulnerable code path. Once processed, memory contents may be read and extracted by the attacker. The risk remains moderate until a patch is applied.
OpenCVE Enrichment