The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP firmware.
The problem resulted from improper bounds checking in DCP firmware. An attacker can provide specially crafted data that exceeds the acceptable ranges processed by the display coprocessor firmware. This can result in system instability or execution of arbitrary code at the DCP firmware level. Apple fixed the vulnerability by implementing improved bounds verification mechanisms.
An attacker can cause unexpected system termination (denial of service) or arbitrary code execution (RCE) in the context of DCP firmware on a vulnerable device.
Devices must be urgently updated to iOS 18.1, iPadOS 18.1, or macOS Sequoia 15.1. Detailed information is available in Apple security bulletins at https://support.apple.com/en-us/121563 and https://support.apple.com/en-us/121564
Apple iOS in versions earlier than 18.1 and Apple iPadOS in versions earlier than 18.1; the vulnerability also affects macOS Sequoia in versions earlier than 15.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApple iPadOS
OSApple< 18.1Apple iOS
OSApple< 18.1
Related vulnerabilities
Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu
Apple — memory corruption (RCE) w przetwarzaniu strumieni audio
Apple: Obejście Pointer Authentication w iOS, macOS i innych platformach
Apple WebKit: out-of-bounds write umożliwiający ucieczkę z sandbox przeglądarki
Use-after-free w Apple iOS/iPadOS/macOS — privilege escalation przez aplikację