Apple tvOS
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*
This vulnerability is being actively exploited in the wild.
A memory corruption vulnerability has been identified in Apple's CoreAudio component, present in multiple operating systems including iOS, iPadOS, macOS, tvOS, and visionOS. This vulnerability allows for code execution by processing an audio stream from a maliciously crafted media file. The issue arises from improper bounds checking, which has been addressed in the latest updates. Apple is aware of reports suggesting that this vulnerability may have been exploited in sophisticated attacks against targeted individuals on iOS.
Exploitation of this vulnerability allows for arbitrary code execution on the affected device.
The vulnerability can be reproduced by creating an audio file that exploits the improper bounds checking in the CoreAudio deserializer for the Apple Positional Audio Codec (APAC). This can be done by manipulating the channel layout tag to create a mismatch that the audio processing pipeline does not properly handle, leading to a memory corruption when the audio is played back.
Users can update to the latest versions of iOS, iPadOS, macOS, tvOS, or visionOS to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.