An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in GarageBand for macOS 10.4.8. Parsing a maliciously crafted MIDI file may lead to an unexpected application termination or arbitrary code execution.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://support.apple.com/en-us/HT213650 | release notes vendor advisory |