VYPR
advisoryPublished Jul 29, 2026· 1 source

Zero-Day Initiative Discloses Critical CoreAudio Vulnerability in macOS

A severe out-of-bounds write vulnerability in Apple's macOS CoreAudio component, ZDI-26-491, allows remote attackers to execute arbitrary code.

The Zero Day Initiative (ZDI) has disclosed a critical vulnerability, tracked as ZDI-26-491, affecting Apple's macOS operating system. This flaw resides within the CoreAudio component, a fundamental part of macOS responsible for audio processing.

Successful exploitation of this vulnerability, which has been assigned a CVSS score of 8.8, allows remote attackers to execute arbitrary code on vulnerable systems. The attack vector requires user interaction, meaning a victim must be tricked into visiting a malicious webpage or opening a specially crafted file. This makes it a significant threat for widespread compromise if exploited.

The specific technical weakness lies in the parsing of APAC streams. Attackers can leverage a lack of proper validation of user-supplied data, leading to a write operation that extends beyond the boundaries of an allocated buffer. This out-of-bounds write condition can be manipulated by attackers to inject and execute their own code within the context of the currently running process, potentially granting them elevated privileges or control over the affected application.

While the exact scope of affected macOS versions has not been detailed beyond the general statement of vulnerability, Apple has acknowledged the issue and released an update to address it. Users are strongly advised to apply the latest security patches provided by Apple to mitigate the risk. Further details on the patch can be found via Apple's support page here.

The disclosure timeline indicates that the vulnerability was initially reported to the vendor on April 23, 2026. Following a coordinated public release of the advisory on July 29, 2026, ZDI also updated its advisory on the same day, suggesting potential new information or refinements to the vulnerability's description or impact.

The vulnerability was reported by an anonymous researcher, highlighting the ongoing efforts of security professionals to uncover and report critical flaws. The coordinated disclosure process, managed by ZDI, aims to provide vendors with adequate time to develop and deploy patches before the vulnerability becomes widely known and exploited.

This discovery underscores the persistent need for vigilance in software security, even within mature operating systems like macOS. CoreAudio, being a core component, means that vulnerabilities within it can have far-reaching implications for the stability and security of the entire system. Users should maintain up-to-date systems and exercise caution when interacting with external content.

The Zero Day Initiative is a well-known bug bounty program that facilitates the responsible disclosure of security vulnerabilities. By working with researchers and vendors, ZDI plays a crucial role in improving the security posture of software products worldwide.

Synthesized by Vypr AI