The release notes do say what the bugs are and some about how they are exploited.
To me, it doesn’t mean anything. Never heard of CoreAudio. Okay, so it’s about code that could be executed while streaming music. So that would mean Spotify, AM, videos from the web in Safari I presume? And then what? Code could be run. But the writer of said code doesn’t know who he’s attacking, so it’s some general exploit. What could the ramifications be?
I really don’t get any of these bugs. I simply never upgrade anymore, and deal with the bugs when I get a new device. May very well be ignorant, but totally fine with it. No need to waste time on updating software, rebooting, et cetera.