PT-2025-16877 · Apple · Visionos+5
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
macOS Sequoia versions prior to 15.4.1
tvOS versions prior to 18.4.1
visionOS versions prior to 2.4.1
iOS versions prior to 18.4.1
iPadOS versions prior to 18.4.1
watchOS versions prior to 11.5
Description
A memory corruption issue exists in the RPAC and CoreAudio components due to out-of-bounds memory reads. Processing an audio stream within a maliciously crafted media file can allow a remote attacker to bypass security restrictions or execute arbitrary code. This issue involves the
InferProfileFromCodecConfigs() function, where improper bounds checking occurs when indexing into global arrays using calculated step sizes related to Higher Order Ambisonics (a method of representing sound as a spatial sound-field). There are reports that this issue has been exploited in extremely sophisticated attacks targeting specific individuals on iOS.Recommendations
Update macOS Sequoia to version 15.4.1.
Update tvOS to version 18.4.1.
Update visionOS to version 2.4.1.
Update iOS to version 18.4.1.
Update iPadOS to version 18.4.1.
Update watchOS to version 11.5.
Exploit
Fix
RCE
DoS
Memory Corruption
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apple Macos
Ios
Ipados
Macos Sequoia
Tvos
Visionos