CVE-2026-91962: FreeRDP before 3.31.0 Integer Overflow via audin Apple backends
FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSGSNDINOPEN messages. Attackers can supply crafted FramesPerPacket values that cause AudioQueueAllocateBuffer size computation to wrap, resulting in undersized buffer allocation and potential out-of-bounds access.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
Deployments running FreeRDP versions earlier than 3.31.0 are affected when they use the audin Apple backends to process MSG_SNDIN_OPEN audio-input messages.
What does exploitation require from an attacker?
The attacker must be able to supply a crafted MSG_SNDIN_OPEN message containing a malicious FramesPerPacket value. The supplied metrics indicate network reachability, no required privileges, and required user interaction.
How can I determine whether a system is vulnerable?
Check the installed FreeRDP version and whether the audin Apple backends are in use. A version earlier than 3.31.0 in that affected processing path is vulnerable.