Junglewise Threat Intelligence

CVE-2026-39869: Apple multiple operating systems memory corruption in Audio

CVE-2026-39869 · Severity: medium · CVSS 4.3 · Published 2026-05-11

Technologies: Apple Tvos, Apple watchOS, Apple Visionos, Apple macOS Sonoma, Apple iPadOS. Vendors: Apple.

Executive brief

A vulnerability in the way Apple operating systems handle audio data could allow a malicious media file to crash an application. This affects a wide range of devices including iPhones, iPads, and Macs. If a user opens a specially crafted audio or video file, the program playing it may suddenly close, potentially causing a loss of unsaved work or a temporary service disruption. Apple has released software updates to fix this issue by improving how the system manages memory during audio processing.

Technical details

A memory handling vulnerability exists in the Audio component of Apple's operating systems. The flaw is triggered when the system processes a specifically crafted audio stream within a media file. An attacker can exploit this by tricking a user into opening a malicious file, leading to an unexpected process termination (Denial of Service). The root cause was addressed by Apple through improved memory handling logic. The vulnerability affects iOS, iPadOS, macOS (Sequoia, Sonoma, and Tahoe), tvOS, visionOS, and watchOS. Patches are available in the May 2026 security updates.

Affected products

  • Apple iOS Before 18.7.9, before 26.5
  • Apple iPadOS Before 18.7.9, before 26.5
  • Apple macOS Sequoia Before 15.7.7
  • Apple macOS Sonoma Before 14.8.7
  • Apple macOS Tahoe Before 26.5
  • Apple tvOS Before 26.5
  • Apple visionOS Before 26.5
  • Apple watchOS Before 26.5

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: patched
  • 2026-05-11: advisory

References

Related threats