Junglewise Threat Intelligence

CVE-2026-43744: Apple multiple operating systems out-of-bounds write in audio processing

CVE-2026-43744 · Severity: info · Published 2026-07-27

Technologies: Apple Tvos, Apple macOS Tahoe, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A vulnerability exists in Apple's operating systems, including iOS, macOS, and watchOS, when processing audio streams. An attacker could use a specially crafted media file to cause an application to crash or behave unexpectedly. This could lead to service interruptions or potential instability on affected iPhones, iPads, Macs, and Apple Watches.

Technical details

An out-of-bounds write vulnerability was identified in the media processing components of various Apple operating systems. The flaw is triggered when the system processes a maliciously crafted audio stream within a media file. The root cause is insufficient bounds checking, which can lead to memory corruption and process termination. An attacker could exploit this by tricking a user into opening a malicious media file or visiting a website hosting such content. Apple has addressed the issue by improving bounds checking in the affected components.

Affected products

  • Apple iOS and iPadOS Before 26.6
  • Apple macOS Sequoia Before 15.7.8
  • Apple macOS Sonoma Before 14.8.8
  • Apple macOS Tahoe Before 26.6
  • Apple tvOS Before 26.6
  • Apple visionOS Before 26.6
  • Apple watchOS Before 26.6

Timeline

  • 2026-07-27: advisory
  • 2026-07-27: patched

References

Related threats