ZeroHour

Vulnerabilities

67 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-65381
Sandbox Escape via Improper Entitlement Validation in Apple macOS

CVE-2026-65381 is a missing-authorization flaw (CWE-862) in Apple macOS's entitlement verification, where the system failed to properly validate the entitlements of a running process. Per Apple's advisory, the practical trigger is a malicious app already executing on a Mac: by abusing the weak entitlement check, the app can break out of its App Sandbox confinement. A successful escape lets the attacker's code operate outside the sandbox's restrictions, potentially exposing resources and privileges the sandbox was meant to contain, though Apple does not detail a specific escalation to kernel or root. All Mac users running affected macOS releases are exposed in principle: macOS Sequoia before 15.8, macOS Tahoe before 26.7, and macOS Golden Gate before version 27. There is no evidence of exploitation: the issue is not in CISA KEV, and no public proof-of-concept or in-the-wild reports are known. Note that the feed's CVSS 3.1 score of 10 uses a network vector (AV:N), while Apple's description frames exploitation as requiring a locally running malicious app, so real-world exploitability depends on getting a malicious app onto the target.

Do: Update affected Macs to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27 (or later) via System Settings > Software Update. Until patched, avoid installing or running untrusted third-party applications, since exploitation requires a malicious app to execute locally. Check fleet inventory for devices stuck on pre-fix Sequoia or Tahoe builds and prioritize them for patching.

10.0
group max
  • Apple macOS Sequoia all versions prior to 15.8
  • Apple macOS Tahoe all versions prior to 26.7
  • Apple macOS Golden Gate all versions prior to 27
masson the order of 100 million+ active Macs running affected macOS versions (practical risk limited to devices that run a malicious app)
CVE-2026-84561
Kernel Double-Free in Apple iOS, iPadOS, macOS, tvOS, visionOS and watchOS

CVE-2026-84561 is a double-free memory-corruption flaw (CWE-415) in the kernel of Apple's operating systems, resolved through improved memory management. Although the CVSS vector is scored with a network attack vector, Apple's advisory describes a locally running app as the trigger: a malicious or compromised app on the device can trip the double free in kernel code. The result, per Apple, is unexpected system termination or corruption of kernel memory — a denial-of-service condition, with kernel memory corruption potentially usable as a building block for further exploitation. All users of iPhones, iPads, Macs, Apple TVs, Apple Vision Pro headsets and Apple Watches running versions older than the fixed releases are affected. There is currently no evidence of in-the-wild exploitation, no CISA KEV listing, and no known public proof-of-concept.

Do: Update devices to iOS/iPadOS 26.7 or 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, tvOS 27, visionOS 27 or watchOS 27. Verify fleet OS versions via MDM or Settings > General > Software Update and prioritize user-facing iOS/macOS devices. Until patched, limit risk by avoiding untrusted app installs, since a local app is the documented trigger; no other workaround is available.

9.8
group max
  • Apple iOS prior to 26.7 and prior to 27 (fixed in iOS 26.7 and iOS 27)
  • Apple iPadOS prior to 26.7 and prior to 27 (fixed in iPadOS 26.7 and iPadOS 27)
  • Apple macOS Sequoia prior to 15.8 (fixed in macOS Sequoia 15.8)
  • +5 more
massroughly 2 billion active Apple devices (iPhone, iPad, Mac, Apple TV, Apple Watch, Vision Pro) on pre-fix OS versions
CVE-2026-65391
+1 in the same advisory: …65390
Out-of-Bounds Write in Apple Safari/WebKit Web Content Rendering

CVE-2026-65391 is an out-of-bounds write (CWE-190, integer overflow/wraparound) in Apple's web content processing engine, fixed with improved bounds checking. It is triggered when a victim simply visits a maliciously crafted web page in Safari or any WebKit-based view, requiring no privileges but some user interaction (CVSS 3.1: 8.8). Successful exploitation causes memory corruption, plausibly yielding arbitrary code execution within the browser/renderer context with high impact on confidentiality, integrity, and availability. Affected software includes Safari and the WebKit engine bundled with iOS/iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS, all patched in the versions listed below. There is no known public proof-of-concept, no confirmed in-the-wild exploitation, and the flaw is not on the CISA KEV list.

Do: Patch immediately: update macOS Tahoe to 26.6.2 (or Safari to 26.6.1), iOS/iPadOS to 26.6.1, and tvOS, visionOS, and watchOS to 27. Enable automatic software updates on all Apple devices, and use MDM to force patch rollout in managed fleets. Because the attack vector is malicious web content, users on unpatched devices should avoid browsing untrusted sites until updated; defenders should watch for post-patch anomaly reports and Apple's security advisory for any exploitation addendum.

8.8
  • Apple Safari (macOS) versions prior to 26.6.1
  • Apple iOS versions prior to 26.6.1
  • Apple iPadOS versions prior to 26.6.1
  • +4 more
mass≈1 billion+ devices (Safari/WebKit ships by default on essentially all iPhones, iPads, and Macs, plus Apple TV, Watch, and Vision Pro)