Vulnerabilities
19 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-43692 | Input Validation RCE Flaw in Apple macOS (Sequoia, Tahoe, Golden Gate) CVE-2026-43692 is an input validation and sanitization weakness in Apple's macOS that allows a remote attacker to cause unexpected application termination or execute arbitrary code on an affected Mac. The exact component and attack vector were not specified in the advisory, but flaws of this class are typically triggered by tricking a target into processing maliciously crafted content or input, and exploitation would let an attacker crash apps or run code in the context of the vulnerable process. All Macs running macOS Sequoia before 15.8, macOS Tahoe before 26.7, or macOS Golden Gate before 27 are affected; Apple patched the issue in those releases, which shipped alongside the company's broad September security updates. The vulnerability has no CVSS score yet, no public proof-of-concept is known, and it is not listed in CISA's Known Exploited Vulnerabilities catalog, indicating no observed in-the-wild exploitation at this time. Do: Update affected Macs immediately to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27 (or later) via System Settings > Software Update, and prioritize the update in MDM/patch management since arbitrary code execution flaws in macOS are prime targets once details emerge. There is no published workaround, so patching is the primary mitigation. After patching, monitor Apple's security advisory and threat intel feeds for the affected component and any emerging exploitation before this CVE receives a CVSS score. | 8.8 group max | — |
| massPotentially hundreds of millions of Macs; Apple's active Mac installed base is commonly estimated at well over 100 million devices, most running the affected… | ||
| CVE-2026-84607 | Sandbox-Escaping Kernel Race Condition in Apple iOS, macOS, and Other OSes CVE-2026-84607 is a race condition (CWE-362) in Apple's operating systems that was fixed with improved state management, allowing a sandboxed app to execute arbitrary code with kernel privileges. Exploitation requires a malicious or compromised app already running on the device (local vector, low privileges, no user interaction), which then abuses a timing window in kernel state handling to break out of the sandbox. A successful exploit yields full kernel-level code execution — the highest privilege tier on Apple platforms — making this a prime component for chaining with initial-code-execution bugs such as browser or app flaws. All iPhones, iPads, Macs, Apple TVs, Apple Watches, and Vision Pros running OS versions older than the listed fixes are affected. No public proof of concept exists, the flaw is not on CISA's KEV list, and no exploitation in the wild has been reported. Do: Patch all Apple devices to the fixed releases — iOS/iPadOS 26.7 or 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27 — and use MDM to push and verify updates fleet-wide. Because this flaw converts any sandboxed-app foothold into kernel code execution, it is a high-value chaining link; restrict sideloaded or untrusted apps and monitor for anomalous behavior from third-party software on unpatched devices. | 7.8 group max | — |
| masspotentially hundreds of millions of devices (subset of Apple's ~2B+ active devices not yet updated) |