Description
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted audio file may corrupt process memory.
Published: 2026-07-27
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A mismanagement of memory during audio file processing can corrupt process memory when a maliciously crafted audio file is presented. The compromise arises from flawed handling of audio data in the system’s media stack, potentially overwriting or altering memory regions. If the corrupted memory region belongs to an actively running process, this could lead to an application crash or denial of service. The underlying flaw aligns with CWE-119.

Affected Systems

Apple iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6. All listed operating systems incorporate the vulnerable audio handling components and are affected by the memory corruption flaw.

Risk and Exploitability

Exploitation requires crafting a malicious audio file that can corrupt process memory when processed by the vulnerable audio handling components. The flaw is a classic buffer overflow (CWE-119). With a CVSS score of 7.8, this vulnerability is considered high severity. The attack vector is not explicitly documented, but any channel that allows a device to process an audio file could be used. The EPSS score of <1% indicates a low exploitation probability, and the flaw is not listed in the CISA KEV catalog, suggesting public exploitation may be limited. Nonetheless, the absence of a KEV listing does not diminish the need for timely remediation.

Generated by OpenCVE AI on August 4, 2026 at 23:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest software for iOS, iPadOS, macOS, tvOS, visionOS, and watchOS to receive the improved memory handling fix
  • Ensure automatic updates are enabled or manually install each update via Settings > General > Software Update
  • Avoid opening or executing audio files from untrusted sources

Generated by OpenCVE AI on August 4, 2026 at 23:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Malicious Audio File May Corrupt Process Memory

Tue, 04 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title Memory Corruption via Malicious Audio File Leading to Crash
Weaknesses CWE-125
CWE-787

Thu, 30 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Memory Corruption via Malicious Audio File Leading to Crash
Weaknesses CWE-125
CWE-787

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted audio file may corrupt process memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T14:58:10.814Z

Reserved: 2026-05-01T22:46:21.640Z

Link: CVE-2026-43673

cve-icon Vulnrichment

Updated: 2026-07-28T14:58:05.878Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:16:52.657

Modified: 2026-07-28T19:31:29.167

Link: CVE-2026-43673

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T23:45:02Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer