ZDI-CAN-26783: ZDI-25-299: Apple macOS acv2 Codec Converter Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Apple macOS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2025-31208.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-26783?
The severity of ZDI-CAN-26783 is determined by the potential for sensitive information disclosure on affected installations of Apple macOS.
How do I fix ZDI-CAN-26783?
To fix ZDI-CAN-26783, ensure that your Apple macOS is updated to the latest version that addresses this vulnerability.
What type of attack does ZDI-CAN-26783 involve?
ZDI-CAN-26783 involves a remote attacker needing user interaction to exploit the vulnerability through a malicious page or file.
Which versions of macOS are affected by ZDI-CAN-26783?
ZDI-CAN-26783 affects installations of Apple macOS that have not been updated to address the vulnerability.
Is user interaction required to exploit ZDI-CAN-26783?
Yes, user interaction is required for an attack exploiting ZDI-CAN-26783, as the target must visit a malicious page or open a malicious file.