Vulnerabilities
64 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-84561 | Kernel Double-Free in Apple iOS, iPadOS, macOS, tvOS, visionOS and watchOS CVE-2026-84561 is a double-free memory-corruption flaw (CWE-415) in the kernel of Apple's operating systems, resolved through improved memory management. Although the CVSS vector is scored with a network attack vector, Apple's advisory describes a locally running app as the trigger: a malicious or compromised app on the device can trip the double free in kernel code. The result, per Apple, is unexpected system termination or corruption of kernel memory — a denial-of-service condition, with kernel memory corruption potentially usable as a building block for further exploitation. All users of iPhones, iPads, Macs, Apple TVs, Apple Vision Pro headsets and Apple Watches running versions older than the fixed releases are affected. There is currently no evidence of in-the-wild exploitation, no CISA KEV listing, and no known public proof-of-concept. Do: Update devices to iOS/iPadOS 26.7 or 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, tvOS 27, visionOS 27 or watchOS 27. Verify fleet OS versions via MDM or Settings > General > Software Update and prioritize user-facing iOS/macOS devices. Until patched, limit risk by avoiding untrusted app installs, since a local app is the documented trigger; no other workaround is available. | 9.8 group max | — |
| massroughly 2 billion active Apple devices (iPhone, iPad, Mac, Apple TV, Apple Watch, Vision Pro) on pre-fix OS versions | ||
| CVE-2026-65381 | Sandbox Escape via Improper Entitlement Validation in Apple macOS CVE-2026-65381 is a missing-authorization flaw (CWE-862) in Apple macOS's entitlement verification, where the system failed to properly validate the entitlements of a running process. Per Apple's advisory, the practical trigger is a malicious app already executing on a Mac: by abusing the weak entitlement check, the app can break out of its App Sandbox confinement. A successful escape lets the attacker's code operate outside the sandbox's restrictions, potentially exposing resources and privileges the sandbox was meant to contain, though Apple does not detail a specific escalation to kernel or root. All Mac users running affected macOS releases are exposed in principle: macOS Sequoia before 15.8, macOS Tahoe before 26.7, and macOS Golden Gate before version 27. There is no evidence of exploitation: the issue is not in CISA KEV, and no public proof-of-concept or in-the-wild reports are known. Note that the feed's CVSS 3.1 score of 10 uses a network vector (AV:N), while Apple's description frames exploitation as requiring a locally running malicious app, so real-world exploitability depends on getting a malicious app onto the target. Do: Update affected Macs to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27 (or later) via System Settings > Software Update. Until patched, avoid installing or running untrusted third-party applications, since exploitation requires a malicious app to execute locally. Check fleet inventory for devices stuck on pre-fix Sequoia or Tahoe builds and prioritize them for patching. | 10.0 group max | — |
| masson the order of 100 million+ active Macs running affected macOS versions (practical risk limited to devices that run a malicious app) | ||
| CVE-2026-43798 | A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write of attacker-controlled length and content against any applic A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write of attacker-controlled length and content against any application built on swift-nio-ssh. This vulnerability is addressed in swift-nio-ssh version 0.14.1. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2026-65400 | Authentication Bypass in Apple macOS Screen Sharing CVE-2026-65400 is a critical (CVSS 9.8) improper authentication flaw (CWE-287) in Apple macOS's Screen Sharing service, caused by an authentication state-management defect. An attacker who can reach a vulnerable Mac's Screen Sharing service over the network can authenticate without valid credentials, gaining full remote access with high impact to confidentiality, integrity, and availability. All three currently supported macOS branches are affected: Sequoia, Sonoma, and Tahoe, in versions prior to the fixed releases. The flaw is being actively exploited on the internet, with public reporting that attackers use the bypass to deploy Monero cryptominers, and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-18. EPSS estimates a 9.9% probability of exploitation within 30 days (95th percentile). Do: Upgrade to macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, or macOS Tahoe 26.6.1 (or later) immediately; patching is mandatory for federal agencies under CISA BOD 26-04 given the KEV listing. As an interim mitigation, disable Screen Sharing or restrict it via firewall/VPN so VNC (port 5900) is not reachable from the internet. Review internet-exposed Macs for signs of compromise, especially unexplained Monero miner processes or abnormal CPU usage. | 9.8 | 10% | KEV |
| masson the order of 100M+ Macs run affected macOS versions; the directly exploitable subset is Macs with Screen Sharing enabled and internet-reachable | |
| CVE-2026-43810 | The issue was addressed with improved memory handling. The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2026-64704 | A type confusion issue was addressed with improved memory handling. A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination. NVD description · AI analysis pending | 9.8 | <1% |
| — |