Executive brief
AppleAVD is a video decoding framework used by iOS, macOS, and other Apple operating systems to process video content. A use-after-free memory vulnerability allows an app to cause unexpected system crashes, potentially disrupting device functionality or enabling a malicious app to destabilize the system.
Technical details
The vulnerability is a use-after-free issue in Apple's AppleAVD component, addressed through improved memory management. The flaw occurs when memory is accessed after it has been freed, potentially allowing an attacker to cause denial-of-service by crashing the system. An app with execution privileges can trigger this condition without requiring elevated permissions. The vulnerability affects multiple Apple platforms including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. Fixes are available in iOS 26.6+, iPadOS 26.6+, macOS Tahoe 26.6+, macOS Golden Gate 27, macOS Sequoia 15.8, tvOS 26.6+, visionOS 26.6+, and watchOS 26.6+.
Affected products
- Apple iOS before 26.6, before 26.7, before 27
- Apple iPadOS before 26.6, before 26.7, before 27
- Apple macOS Tahoe before 26.6, before 26.7
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple tvOS before 26.6, before 27
- Apple visionOS before 26.6, before 27
- Apple watchOS before 26.6, before 27
Timeline
- 2026-09-14: disclosed
- 2026-07-27: patched: Initial patch released for iOS 26.6, iPadOS 26.6, and macOS Tahoe 26.6