ZeroHour

Vulnerabilities

143 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-84520
Kernel buffer overflow in Apple macOS (fixed in Golden Gate 27)

CVE-2026-84520 is a buffer overflow (CWE-120) in the macOS kernel caused by insufficient size validation, which Apple addresses with improved bounds checking in the macOS Golden Gate 27 release. A local attacker — meaning someone already able to execute code on the targeted Mac — can trigger the flaw to corrupt kernel memory or cause unexpected system termination. Kernel memory corruption can crash the machine and may open the door to privilege escalation, though no public proof-of-concept exists and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog. Any Mac running a macOS version older than Golden Gate 27 is potentially affected, which at disclosure covers essentially the entire installed base. Note that the published CVSS 9.8 score models an unauthenticated network vector, but Apple's advisory describes a local attack requirement, so unauthenticated remote exploitation is not indicated by the source data.

Do: Upgrade affected Macs to macOS Golden Gate 27 (or later) via System Settings > Software Update as soon as the release is available for your hardware. Because the attack requires local access, restrict untrusted local code execution on managed Macs until patched. Verify the installed OS version under About This Mac and monitor Apple security pages for any backported fixes to earlier macOS releases.

9.8
group max
  • Apple macOS (kernel) All macOS versions prior to Golden Gate 27 (the release containing the fix; specific earlier releases are not enumerated in the source data)
mass≈100M+ active Macs
CVE-2026-65414
Out-of-Bounds Write in Apple iOS, iPadOS, macOS Enables Remote Code Execution

Apple patched a critical out-of-bounds write (CWE-787) memory-corruption flaw spanning nearly its entire operating-system lineup: iOS, iPadOS, macOS (Sequoia, Tahoe, Golden Gate), tvOS, visionOS, and watchOS. A remote attacker could trigger the flaw with no privileges and no user interaction (CVSS 3.1: 9.8, network vector, low complexity), causing unexpected app termination or potentially arbitrary code execution on the affected device. The advisory does not identify the vulnerable component or exact trigger, so defenders should assume any affected system is remotely attackable until patched. All users running iOS/iPadOS before 26.7, macOS Sequoia before 15.8, macOS Tahoe before 26.7, or pre-release tvOS/visionOS/watchOS builds older than 27 are affected. No public proof of concept exists, no exploitation in the wild is known, and the flaw is not on CISA's KEV list; fixes shipped in the listed updates.

Do: Update all Apple devices promptly: iPhones/iPads to iOS/iPadOS 26.7 or 27, Macs to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27, Apple TV to tvOS 27, Apple Watch to watchOS 27, and Vision Pro to visionOS 27. Enable automatic security updates and use MDM/inventory to find devices still on older OS trains. Given the 9.8 CVSS with no user interaction required, treat patching as high priority even though no exploitation has been observed.

9.8
group max
  • Apple iOS Prior to iOS 26.7 (26.x and earlier trains); fixed in iOS 26.7 and iOS 27
  • Apple iPadOS Prior to iPadOS 26.7 (26.x and earlier trains); fixed in iPadOS 26.7 and iPadOS 27
  • Apple macOS Sequoia Prior to 15.8; fixed in 15.8
  • +5 more
masspotentially 1+ billion devices (Apple's ~2.35 billion active-device install base, most on affected OS trains)
CVE-2026-65391
+2 in the same advisory: …65390 …84518
Out-of-Bounds Write in Apple Safari/WebKit Web Content Rendering

CVE-2026-65391 is an out-of-bounds write (CWE-190, integer overflow/wraparound) in Apple's web content processing engine, fixed with improved bounds checking. It is triggered when a victim simply visits a maliciously crafted web page in Safari or any WebKit-based view, requiring no privileges but some user interaction (CVSS 3.1: 8.8). Successful exploitation causes memory corruption, plausibly yielding arbitrary code execution within the browser/renderer context with high impact on confidentiality, integrity, and availability. Affected software includes Safari and the WebKit engine bundled with iOS/iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS, all patched in the versions listed below. There is no known public proof-of-concept, no confirmed in-the-wild exploitation, and the flaw is not on the CISA KEV list.

Do: Patch immediately: update macOS Tahoe to 26.6.2 (or Safari to 26.6.1), iOS/iPadOS to 26.6.1, and tvOS, visionOS, and watchOS to 27. Enable automatic software updates on all Apple devices, and use MDM to force patch rollout in managed fleets. Because the attack vector is malicious web content, users on unpatched devices should avoid browsing untrusted sites until updated; defenders should watch for post-patch anomaly reports and Apple's security advisory for any exploitation addendum.

8.8
group max
  • Apple Safari (macOS) versions prior to 26.6.1
  • Apple iOS versions prior to 26.6.1
  • Apple iPadOS versions prior to 26.6.1
  • +4 more
mass≈1 billion+ devices (Safari/WebKit ships by default on essentially all iPhones, iPads, and Macs, plus Apple TV, Watch, and Vision Pro)
CVE-2026-65393
macOS Permission Validation Flaw Lets Apps Access User-Sensitive Data

CVE-2026-65393 is a permissions/validation weakness in Apple's macOS (and related tooling in Xcode) in which an app running on an affected system may be able to access user-sensitive data that it should not be permitted to read. Exploitation requires a malicious or compromised application to already be present and executing on the victim's Mac, where it abuses the insufficient permission validation rather than a remotely reachable network flaw. A successful abuser gains access to sensitive user data (for example, data protected by macOS privacy controls), but there is no indication of arbitrary code execution or remote compromise. The issue affects users running macOS versions prior to macOS Golden Gate 27, as well as developers on Xcode versions prior to Xcode 27, since fixes shipped in both releases as part of a large Apple security update. There is no known public proof-of-concept, no confirmed in-the-wild exploitation, and the CVE is not in the CISA KEV catalog.

Do: Update to macOS Golden Gate 27 as soon as practical, and developers should move to Xcode 27 so apps are built against the corrected validation behavior. In the interim, audit installed applications and the permissions granted under System Settings > Privacy & Security, revoking unusual data-access grants and removing untrusted apps, since exploitation depends on a malicious app already running locally. Monitor Apple's security advisory and threat feeds, as this flaw was patched alongside a very large batch of fixes that attackers may prioritize for reverse engineering.

5.5
  • Apple macOS Golden Gate versions prior to macOS Golden Gate 27 (fixed in macOS Golden Gate 27)
  • Apple Xcode versions prior to Xcode 27 (fixed in Xcode 27)
mass≈100M+ users (Apple's active Mac installed base is well over 100 million devices)