Mackron develops a focused set of lightweight audio and data-processing libraries—most notably miniaudio and dr_libs—that are widely embedded in games, media applications, and embedded systems despite their small product count. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and cluster around memory-safety weaknesses including heap-based buffer overflows, classic buffer overflows, double frees, and improper null termination that are characteristic of C-based audio and parsing code exposed to untrusted input. Defenders should prioritize inventory of products that bundle these libraries and apply updates promptly, as supply-chain exposure can be broad; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mackron over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-34184CRITICAL Miniaudio 0.10.35 has a Double free vulnerability that could cause a buffer overflow in ma_default_vfs_close__stdio in miniaudio.h. | Jun 25, 2021 | 9.8 | 30 | NO | NO |
CVE-2026-29022HIGH dr_libs dr_wav.h version 0.14.4 and earlier (fixed in commit 8a7258c) contain a heap buffer overflow vulnerability in the drwav__read_smpl_to_metadata_obj() function of dr_wav.h th | Mar 3, 2026 | 7.8 | 29 | NO | NO |
CVE-2024-41147CRITICAL An out-of-bounds write vulnerability exists in the ma_dr_flac__decode_samples__lpc functionality of Miniaudio miniaudio v0.11.21. A specially crafted .flac file can lead to memory | Mar 4, 2025 | 9.8 | 29 | NO | NO |
CVE-2026-32836MEDIUM dr_libs dr_flac.h version 0.13.3 and earlier (fixed in commits fefced4, 4f5a4cd, and 663239a) contain an uncontrolled memory allocation vulnerability in drflac__read_and_decode_met | Mar 17, 2026 | 6.2 | 24 | NO | NO |
CVE-2026-32837MEDIUM miniaudio version 0.11.25 and earlier (fixed in commits 1df46ae and 1df46ae) contain a heap out-of-bounds read vulnerability in the WAV BEXT metadata parser that allows attackers t | Mar 17, 2026 | 5.5 | 22 | NO | NO |
CVE-2021-34185HIGH Miniaudio 0.10.35 has an integer-based buffer overflow caused by an out-of-bounds left shift in drwav_bytes_to_u32 in miniaudio.h | Jun 25, 2021 | 7.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mackron.
Media articles that mention a CVE ID that affects a product developed by Mackron — matched by CVE ID, not by vendor name.