
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20611 is an out-of-bounds access vulnerability in Apple's CoreAudio component, specifically affecting the decoding of audio APAC frames. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory. It was disclosed and patched on February 11, 2026, affecting iOS/iPadOS (before 18.7.5 and 26.3), macOS Sonoma (before 14.8.4), macOS Sequoia (before 15.7.4), macOS Tahoe (before 26.3), tvOS (before 26.3), watchOS (before 26.3), and visionOS (before 26.3). The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Apple iOS 26.3 Advisory, Apple iOS 18.7.5 Advisory).
The root cause is insufficient bounds checking during the parsing of audio APAC frames in Apple's CoreAudio framework, classified as CWE-125 (Out-of-bounds Read). The vulnerability results from a write operation that extends past the end of an allocated buffer when processing maliciously crafted media content. Exploitation requires local access and user interaction — specifically, a user must open a malicious media file — making the attack vector local with no privileges required. A proof-of-concept advisory was published by Trend Micro's Zero Day Initiative (ZDI-26-173), and the vulnerability was reported by an anonymous researcher working with Trend Micro ZDI (ZDI Advisory, Apple watchOS 26.3 Advisory).
Successful exploitation can result in unexpected application termination (denial of service) or corruption of process memory, which may be leveraged to achieve arbitrary code execution in the context of the vulnerable application. Given the high confidentiality, integrity, and availability impact scores, a successful attack could lead to data theft, system compromise, or further malware installation on the affected device. The vulnerability affects a broad range of Apple platforms — iPhone, iPad, Mac, Apple Watch, Apple TV, and Apple Vision Pro — significantly widening the potential attack surface (Apple macOS Sequoia Advisory, Apple visionOS 26.3 Advisory).
coreaudiod, Music, QuickTime Player, or third-party apps using CoreAudio) on unpatched Apple devices./Library/Logs/DiagnosticReports/ on macOS or via Settings > Privacy > Analytics on iOS) referencing CoreAudio or APAC-related stack traces with out-of-bounds memory access signals..caf, .m4a, .aac) received from unknown sources in Downloads, Mail attachments, or messaging app caches.Apple released patches on February 11, 2026, addressing this vulnerability across all affected platforms. Users should update to the following versions or later: iOS/iPadOS 18.7.5, iOS 26.3 / iPadOS 26.3, macOS Sonoma 14.8.4, macOS Sequoia 15.7.4, macOS Tahoe 26.3, tvOS 26.3, watchOS 26.3, and visionOS 26.3. As a precautionary measure prior to patching, users should avoid opening media files from untrusted or unknown sources. No configuration-based workaround is available; applying the vendor patch is the only definitive remediation (Apple iOS 18.7.5 Advisory, Apple macOS Sequoia Advisory, Apple iOS 26.3 Advisory).
The vulnerability was reported by an anonymous researcher working through Trend Micro's Zero Day Initiative, which subsequently published a dedicated advisory (ZDI-26-173) in March 2026 (ZDI Advisory). Security community coverage noted the broad platform scope of the February 2026 Apple patch batch, which addressed over 90 vulnerabilities across macOS, iOS, and iPadOS. No significant independent researcher commentary or notable social media discussion specific to CVE-2026-20611 beyond standard patch-Tuesday coverage has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."