ZDI-26-230: Apple macOS CoreMedia Framework Out-Of-Bounds Write Remote Code Execution Vulnerability

Kurzinfo

Metadaten

  • Original (extern): Link oeffnen
  • Veroeffentlicht: 2026-03-30 05:00 UTC
  • Importiert: 2026-05-15 03:47 UTC
  • CVSS: 6.5
  • Quelle-ID: zdi_pub
  • uid_hash: f1fde3510ddd52c71a7ae5fbd7c34c4ff6e3508fd869a7200a74c559e1523914

Inhalt

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-20690.

Verknuepfte CVEs

CVE-ID CVE-Schwere CVSS (CVE.org) EPSS EPSS-Pctl Veroeffentlicht (CVE.org)

CVE-2026-20690

MEDIUM 6.5 - - 2026-03-25

Quellen-Details

Bezeichnung Name Kategorie Tags Zielgruppe Sprache Feed-URL
Zero Day Initiative (Published)

zdi_pub

threat_intel - de https://www.zerodayinitiative.com/rss/published/