CVE-2026-91962: FreeRDP before 3.31.0 Integer Overflow via audin Apple backends

Published Sep 15, 2026
·
Updated

FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSGSNDINOPEN messages. Attackers can supply crafted FramesPerPacket values that cause AudioQueueAllocateBuffer size computation to wrap, resulting in undersized buffer allocation and potential out-of-bounds access.

Affected Software

1 affected component
FreeRDP<3.31.0

Event History

Sep 15, 2026
CVE Published
via MITRE·03:18 PM
Data Sourced
via MITRE·03:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are affected?

Deployments running FreeRDP versions earlier than 3.31.0 are affected when they use the audin Apple backends to process MSG_SNDIN_OPEN audio-input messages.

2

What does exploitation require from an attacker?

The attacker must be able to supply a crafted MSG_SNDIN_OPEN message containing a malicious FramesPerPacket value. The supplied metrics indicate network reachability, no required privileges, and required user interaction.

3

How can I determine whether a system is vulnerable?

Check the installed FreeRDP version and whether the audin Apple backends are in use. A version earlier than 3.31.0 in that affected processing path is vulnerable.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203