Executive brief
A logic error in Apple's Audio component allows apps to leak sensitive user information on iOS, iPadOS, and macOS devices. This vulnerability could enable malicious apps to extract private data from users without their knowledge, compromising personal privacy across millions of Apple devices.
Technical details
The vulnerability is a logic issue in the Audio framework on Apple platforms that was addressed with improved input validation checks. The flaw allows apps with local access to exploit the Audio component and leak sensitive user information. An attacker would need to craft a malicious app that runs on the targeted device; no network access or user interaction beyond installation is required. The issue was patched in iOS 26.6.1, iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, and watchOS 27.
Affected products
- Apple iOS before 26.6.1
- Apple iPadOS before 26.6.1
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.6.2
- Apple tvOS before 27
- Apple visionOS before 27
- Apple watchOS before 27
Timeline
- 2026-08-17: disclosed: CVE-2026-65339 publicly disclosed
- 2026-08-17: patched: Patches released for iOS 26.6.1, iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27