Executive brief
A memory handling vulnerability exists in Apple operating systems, including iOS, macOS, and watchOS. An attacker could exploit this by tricking a user into opening a specially crafted audio file, which could lead to memory corruption. This type of flaw can potentially allow for unauthorized code execution or system instability.
Technical details
A memory corruption vulnerability exists in the audio processing component of multiple Apple operating systems. The flaw is triggered when the system processes a maliciously crafted audio file, leading to corrupted process memory. This is likely a buffer overflow or similar memory safety issue resulting from improper validation of audio file metadata or stream data. An attacker could potentially achieve arbitrary code execution in the context of the application playing the audio. The vulnerability is fixed in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6.
Affected products
- Apple iOS and iPadOS Before 26.6
- Apple macOS Sequoia Before 15.7.8
- Apple macOS Sonoma Before 14.8.8
- Apple macOS Tahoe Before 26.6
- Apple tvOS Before 26.6
- Apple visionOS Before 26.6
- Apple watchOS Before 26.6
Timeline
- 2026-07-27: disclosed
- 2026-07-27: patched