NTCF:
NTCF-2026-11693
Product:
ALAC
Vendor:
MacOS forge
Criticality:
high
Status:
pending
Discovered:
2026-09-29
Detail:
Public
Vulnerable version:
all
Summary
The open-source Apple Lossless Audio Codec (ALAC) implementation by MacOS forge (https://github.com/macosforge/alac) is vulnerable to a heap-based buffer overflow that potentially allows remote code execution (RCE). In many scenarios, this vulnerability is reachable without authentication over streaming protocols, such as AirPlay. This vulnerability has already lead to several CVEs in affected products in the past, but the upstream implementation has never been fixed (it is an unmaintained archive). The NTC has evidence that there are still actively maintained products that rely on this component and whose developers are unaware of this bug, given there is no CVE assigned to the upstream dependency itself.
Background
Multiple audio streaming devices the NTC has analyzed support AirPlay with the Apple Lossless Audio Codec (ALAC). One possibility for product vendors to include such support is by using an existing open-source implementation of the audio codec, such as ALAC by Mac OS forge (https://github.com/macosforge/alac). This implementation was published in 2011 through Apple's open source initiative, MacOS forge. Unfortunately, the open source implementation has not seen active maintenance by Apple or the open source community. Rather, the software was quickly abandoned after the initial release and no security patches were ever backported.
Given that the upstream dependency is vulnerable, every product that incorporates this component has to manually apply a suitable fix. This is error-prone and given that no public CVE is available at the time of writing, automatic detection through SBOM vulnerability scans (as promoted by the EU Cyber Resilience Act) is difficult. Hence, the NTC has reason to believe that there are still affected products available on the market today whose developers are unaware of this vulnerability.
The NTC did not independently discover this vulnerability. Instead, the vulnerability has lead to multiple CVEs in the past:
-
CVE-2021-0674
-
CVE-2021-0675
-
CVE-2021-30351
- CVE-2022-23747
However, the listed CVEs are registered against affected downstream products and never against the actual root cause: the ALAC implementation itself. For this reason, the NTC wants to bring public attention to this old, but still relevant issue. Ideally, a new CVE identifier can be reserved for the upstream ALAC implementation to improve the detection and mitigation process for affected products.
Vulnerability
Audio streaming using ALAC supports variable frame lengths. The frame length is usually determined by an out-of-band process during stream initialization. The codec allocates static heap buffers with this size. During audio streaming, the data is split up into chunks that fit into the agreed frame length. However, the codec also allows the audio source to stream shorter frame lengths, usually at the end of an audio track (in case there is not enough data to fill up a whole frame).
The root cause of the vulnerability is a missing check in this mechanism: whether the reported frame length is actually shorter than the "normal" frame length, that the buffers have been allocated for. In the ALAC implementation, this assumption is implicit.
The missing check allows an attacker to craft ALAC frames that report a larger frame length than what the buffers have been allocated for, leading to an out-of-bounds write once they are processed by the codec implementation. This vulnerability potentially allows remote code execution (RCE) or creates a denial-of-service (DoS) primitive.
// codec/ALACDecoder.cpp:134
// allocate mix buffers with size frameLength
mMixBufferU = (int32_t *) calloc( mConfig.frameLength * sizeof(int32_t), 1 );
mMixBufferV = (int32_t *) calloc( mConfig.frameLength * sizeof(int32_t), 1 );
// codec/ALACDecoder.cpp:250
// numSamples is overwritten by stream without validation
if ( partialFrame != 0 )
{
numSamples = BitBufferRead( bits, 16 ) << 16;
numSamples |= BitBufferRead( bits, 16 );
}
// codec/ALACDecoder.cpp:316
// numSamples can be larger than frameLength, overflowing mMixBufferU
for (i = 0; i < numSamples; i++ )
{
val = (int32_t) BitBufferRead( bits, 16 );
val = (val << 16) >> shift;
mMixBufferU[i] = val | BitBufferRead( bits, (uint8_t) extraBits );
}
Remediation
There is no official fix available for this vulnerability.
Developers are advised to manually patch the component (e.g., as shown by an upstream GitHub Issue) and remove this deprecated dependency from their code base.
References
- https://nvd.nist.gov/vuln/detail/cve-2021-0674
- https://nvd.nist.gov/vuln/detail/cve-2021-0675
- https://nvd.nist.gov/vuln/detail/cve-2021-30351
- https://nvd.nist.gov/vuln/detail/cve-2022-23747
- https://cpr-zero.checkpoint.com/vulns/cprid-2191/
- https://github.com/macosforge/alac/issues/22
- https://thehackernews.com/2022/04/critical-chipset-bug-opens-millions-of.html