CVE-2026-20611
macOS vulnerability analysis and mitigation

Overview

CVE-2026-20611 is an out-of-bounds access vulnerability in Apple's CoreAudio component, specifically affecting the decoding of audio APAC frames. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory. It was disclosed and patched on February 11, 2026, affecting iOS/iPadOS (before 18.7.5 and 26.3), macOS Sonoma (before 14.8.4), macOS Sequoia (before 15.7.4), macOS Tahoe (before 26.3), tvOS (before 26.3), watchOS (before 26.3), and visionOS (before 26.3). The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Apple iOS 26.3 Advisory, Apple iOS 18.7.5 Advisory).

Technical details

The root cause is insufficient bounds checking during the parsing of audio APAC frames in Apple's CoreAudio framework, classified as CWE-125 (Out-of-bounds Read). The vulnerability results from a write operation that extends past the end of an allocated buffer when processing maliciously crafted media content. Exploitation requires local access and user interaction — specifically, a user must open a malicious media file — making the attack vector local with no privileges required. A proof-of-concept advisory was published by Trend Micro's Zero Day Initiative (ZDI-26-173), and the vulnerability was reported by an anonymous researcher working with Trend Micro ZDI (ZDI Advisory, Apple watchOS 26.3 Advisory).

Impact

Successful exploitation can result in unexpected application termination (denial of service) or corruption of process memory, which may be leveraged to achieve arbitrary code execution in the context of the vulnerable application. Given the high confidentiality, integrity, and availability impact scores, a successful attack could lead to data theft, system compromise, or further malware installation on the affected device. The vulnerability affects a broad range of Apple platforms — iPhone, iPad, Mac, Apple Watch, Apple TV, and Apple Vision Pro — significantly widening the potential attack surface (Apple macOS Sequoia Advisory, Apple visionOS 26.3 Advisory).

Exploitation steps

  1. Craft a malicious media file: Create a specially crafted audio file that exploits improper bounds checking in Apple's CoreAudio APAC frame decoder, triggering an out-of-bounds memory access when parsed.
  2. Deliver the payload: Distribute the malicious file via email attachment, messaging app, malicious website, or file-sharing service targeting users on vulnerable Apple platforms (iOS/iPadOS before 18.7.5 or 26.3, macOS before 14.8.4/15.7.4/26.3, tvOS/watchOS/visionOS before 26.3).
  3. Induce user interaction: Socially engineer the target into opening the malicious media file using a native Apple media application (e.g., Music, QuickTime, or any app using CoreAudio for APAC decoding).
  4. Trigger memory corruption: Upon parsing the malicious APAC frame, the out-of-bounds write corrupts adjacent process memory, potentially leading to application crash or controlled memory manipulation.
  5. Achieve code execution: With a sufficiently refined exploit (as suggested by the ZDI PoC), the memory corruption may be leveraged to redirect execution flow and run arbitrary code in the context of the media-processing application (ZDI Advisory, Apple iOS 26.3 Advisory).

Indicators of compromise

  • Process: Unexpected crashes or terminations of media-handling processes (e.g., coreaudiod, Music, QuickTime Player, or third-party apps using CoreAudio) on unpatched Apple devices.
  • Logs: Crash reports (in /Library/Logs/DiagnosticReports/ on macOS or via Settings > Privacy > Analytics on iOS) referencing CoreAudio or APAC-related stack traces with out-of-bounds memory access signals.
  • File System: Presence of unexpected or suspicious audio/media files (e.g., .caf, .m4a, .aac) received from unknown sources in Downloads, Mail attachments, or messaging app caches.
  • Network: Outbound connections from media-processing applications to unknown external IP addresses following the opening of a media file, which may indicate post-exploitation activity.

Mitigation and workarounds

Apple released patches on February 11, 2026, addressing this vulnerability across all affected platforms. Users should update to the following versions or later: iOS/iPadOS 18.7.5, iOS 26.3 / iPadOS 26.3, macOS Sonoma 14.8.4, macOS Sequoia 15.7.4, macOS Tahoe 26.3, tvOS 26.3, watchOS 26.3, and visionOS 26.3. As a precautionary measure prior to patching, users should avoid opening media files from untrusted or unknown sources. No configuration-based workaround is available; applying the vendor patch is the only definitive remediation (Apple iOS 18.7.5 Advisory, Apple macOS Sequoia Advisory, Apple iOS 26.3 Advisory).

Community reactions

The vulnerability was reported by an anonymous researcher working through Trend Micro's Zero Day Initiative, which subsequently published a dedicated advisory (ZDI-26-173) in March 2026 (ZDI Advisory). Security community coverage noted the broad platform scope of the February 2026 Apple patch batch, which addressed over 90 vulnerabilities across macOS, iOS, and iPadOS. No significant independent researcher commentary or notable social media discussion specific to CVE-2026-20611 beyond standard patch-Tuesday coverage has been identified.

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64776NONEN/A
  • macOS logomacOS
  • Disk Images
NoYesJul 27, 2026
CVE-2026-64775NONEN/A
  • macOS logomacOS
  • Kernel
NoYesJul 27, 2026
CVE-2026-64774NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026
CVE-2026-64772NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management