ZDI-CAN-29143: ZDI-26-491: Apple macOS CoreAudio Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-43673.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-29143?
ZDI-CAN-29143 has a CVSS rating of 8.8, indicating a high-severity vulnerability.
How do I fix ZDI-CAN-29143?
To mitigate ZDI-CAN-29143, users should update their Apple macOS CoreAudio software to the latest available version.
What type of vulnerability is ZDI-CAN-29143?
ZDI-CAN-29143 is classified as an Out-of-Bounds Write vulnerability that can lead to Remote Code Execution.
What are the requirements to exploit ZDI-CAN-29143?
Exploitation of ZDI-CAN-29143 requires user interaction, such as visiting a malicious page or opening a malicious file.
Which software is affected by ZDI-CAN-29143?
ZDI-CAN-29143 affects the Apple macOS CoreAudio component.