Description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing an audio stream in a maliciously crafted media file may terminate the process.
Published: 2026-07-27
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out-of-bounds write triggered when a maliciously crafted audio stream is processed. The insufficient bounds checking causes a memory write beyond the intended buffer which can corrupt memory and bring the targeted application to an unresponsive state, effectively terminating the process. This results in a denial of service and disrupts the normal functionality of the affected software. The weakness aligns with the standard CWE-787 (Out-of-Bounds Write).

Affected Systems

Apple devices running iOS, iPadOS, macOS, tvOS, visionOS, and watchOS with build versions older than the releases that contain the fix are susceptible. Specifically, any iOS or iPadOS instance earlier than 26.6, macOS prior to Sequoia 15.7.8, macOS prior to Sonoma 14.8.8, macOS prior to Tahoe 26.6, tvOS prior to 26.6, visionOS prior to 26.6, and watchOS prior to 26.6 may process the problematic media files, leading to crashes. Apple has addressed the issue in the stated releases, so upgrading removes the vulnerability.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity, and the EPSS score of <1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Since the flaw primarily causes application termination rather than privilege escalation or data disclosure, the risk to confidentiality or integrity is low. Attackers would need to supply or otherwise trick the affected device into handling a malicious audio file, which could be achieved through local or remote media delivery in certain apps. Automated or targeted disruption is possible, so organizations should apply the patch promptly. Once deployed, the corrected bounds checks prevent the out-of-bounds write from occurring, eliminating the crash vector.

Generated by OpenCVE AI on August 3, 2026 at 16:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest software updates that include iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6.
  • Enable automatic updates to ensure future patches are applied promptly.
  • Until a patch is available, avoid playing audio streams from untrusted or unknown sources and consider disabling media playback on vulnerable applications.

Generated by OpenCVE AI on August 3, 2026 at 16:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Apple Audio Processing Leading to Process Termination

Tue, 28 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Apple Audio Processing Leading to Process Termination
Weaknesses CWE-787

Tue, 28 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing an audio stream in a maliciously crafted media file may terminate the process.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T17:55:25.541Z

Reserved: 2026-05-01T22:46:21.647Z

Link: CVE-2026-43744

cve-icon Vulnrichment

Updated: 2026-07-28T17:45:52.094Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:16:59.093

Modified: 2026-07-29T20:28:03.027

Link: CVE-2026-43744

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T16:30:04Z

Weaknesses