ZeroHour

Vulnerabilities

283 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-43692
Input Validation RCE Flaw in Apple macOS (Sequoia, Tahoe, Golden Gate)

CVE-2026-43692 is an input validation and sanitization weakness in Apple's macOS that allows a remote attacker to cause unexpected application termination or execute arbitrary code on an affected Mac. The exact component and attack vector were not specified in the advisory, but flaws of this class are typically triggered by tricking a target into processing maliciously crafted content or input, and exploitation would let an attacker crash apps or run code in the context of the vulnerable process. All Macs running macOS Sequoia before 15.8, macOS Tahoe before 26.7, or macOS Golden Gate before 27 are affected; Apple patched the issue in those releases, which shipped alongside the company's broad September security updates. The vulnerability has no CVSS score yet, no public proof-of-concept is known, and it is not listed in CISA's Known Exploited Vulnerabilities catalog, indicating no observed in-the-wild exploitation at this time.

Do: Update affected Macs immediately to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27 (or later) via System Settings > Software Update, and prioritize the update in MDM/patch management since arbitrary code execution flaws in macOS are prime targets once details emerge. There is no published workaround, so patching is the primary mitigation. After patching, monitor Apple's security advisory and threat intel feeds for the affected component and any emerging exploitation before this CVE receives a CVSS score.

8.8
group max
  • Apple macOS Sequoia before 15.8 (fixed in 15.8)
  • Apple macOS Tahoe before 26.7 (fixed in 26.7)
  • Apple macOS Golden Gate before 27 (fixed in 27)
massPotentially hundreds of millions of Macs; Apple's active Mac installed base is commonly estimated at well over 100 million devices, most running the affected…
CVE-2026-84607
Sandbox-Escaping Kernel Race Condition in Apple iOS, macOS, and Other OSes

CVE-2026-84607 is a race condition (CWE-362) in Apple's operating systems that was fixed with improved state management, allowing a sandboxed app to execute arbitrary code with kernel privileges. Exploitation requires a malicious or compromised app already running on the device (local vector, low privileges, no user interaction), which then abuses a timing window in kernel state handling to break out of the sandbox. A successful exploit yields full kernel-level code execution — the highest privilege tier on Apple platforms — making this a prime component for chaining with initial-code-execution bugs such as browser or app flaws. All iPhones, iPads, Macs, Apple TVs, Apple Watches, and Vision Pros running OS versions older than the listed fixes are affected. No public proof of concept exists, the flaw is not on CISA's KEV list, and no exploitation in the wild has been reported.

Do: Patch all Apple devices to the fixed releases — iOS/iPadOS 26.7 or 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27 — and use MDM to push and verify updates fleet-wide. Because this flaw converts any sandboxed-app foothold into kernel code execution, it is a high-value chaining link; restrict sideloaded or untrusted apps and monitor for anomalous behavior from third-party software on unpatched devices.

7.8
group max
  • Apple iOS prior to 26.7 (26.x line) and prior to 27
  • Apple iPadOS prior to 26.7 (26.x line) and prior to 27
  • Apple macOS Sequoia prior to 15.8
  • +5 more
masspotentially hundreds of millions of devices (subset of Apple's ~2B+ active devices not yet updated)
CVE-2026-64753
Permissions Flaw in Apple Safari and iOS/macOS Lets Web Content Leak User Data

CVE-2026-64753 is an improper privilege management (permissions) vulnerability in Apple's browser and operating system software that Apple fixed by removing the vulnerable code. It is triggered when a device processes maliciously crafted web content — typically a user visiting an attacker-controlled webpage — requiring user interaction but no privileges or attacker access to the device. Successful exploitation can disclose sensitive user information, reflected in a CVSS 3.1 base score of 6.5 (network vector, low attack complexity, high confidentiality impact, no integrity or availability impact). The flaw affects Safari and Apple's full OS lineup before the version 27 release wave — iOS, iPadOS, macOS Golden Gate, tvOS, visionOS, and watchOS — which shipped as part of a broad Apple update addressing 273 vulnerabilities. No public proof of concept is known, the issue is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been confirmed.

Do: Update all Apple devices and browsers to the fixed releases: Safari 27, iOS/iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27, prioritizing iPhones and Macs used for web browsing. Because exploitation requires a user to load malicious web content, advise users to avoid untrusted links until patched. IT admins should verify update compliance across managed device fleets and monitor for post-update browsing anomalies indicating possible information disclosure.

6.5
  • Apple Safari versions prior to Safari 27
  • Apple iOS versions prior to iOS 27
  • Apple iPadOS versions prior to iPadOS 27
  • +4 more
masslikely >1 billion users/devices potentially exposed before patching
CVE-2026-65367
A null pointer dereference was addressed with improved input validation.

A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5. An app may be able to cause unexpected system termination.

NVD description · AI analysis pending
5.5<1%
  • apple ipados
  • apple iphone os
CVE-2026-64705
A buffer overflow was addressed with improved bounds checking.

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or write kernel memory.

NVD description · AI analysis pending
5.5<1%
  • apple macos
CVE-2026-43670
A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts.

A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may bypass Content Security Policy.

NVD description · AI analysis pending
8.8<1%
  • apple safari
  • apple ipados
  • apple iphone os
  • +1 more
CVE-2026-43657
A permissions issue was addressed with additional restrictions.

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and iPadOS 26.5. A malicious app may be able to enumerate installed apps.

NVD description · AI analysis pending
3.3<1%
  • apple iphone os
CVE-2026-43679
This issue was addressed with improved permissions checking.

This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An attacker with physical access to a locked Apple Watch may be able to view user contacts.

NVD description · AI analysis pending
2.4<1%
  • apple watchos
CVE-2026-20679
The issue was addressed with improved checks.

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. Processing a maliciously crafted file may lead to unexpected app termination.

NVD description · AI analysis pending
4.3<1%
  • apple macos
CVE-2026-64773
+1 in the same advisory: …64777
An attacker that can reach a container's published TCP port may be able to force the host's forwarding process to buffer an unbounded amount of that client's da

An attacker that can reach a container's published TCP port may be able to force the host's forwarding process to buffer an unbounded amount of that client's data in memory, for as long as the backend container connection takes to complete — with no cap on how much accumulates or how long the wait can be stretched. This vulnerability is addressed in container version 1.2.0.

NVD description · AI analysis pending
7.5
group max
<1%
  • apple container
CVE-2026-43798
A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write of attacker-controlled length and content against any applic

A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write of attacker-controlled length and content against any application built on swift-nio-ssh. This vulnerability is addressed in swift-nio-ssh version 0.14.1.

NVD description · AI analysis pending
9.8<1%
  • apple swiftnio ssh
CVE-2026-43678
An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent after a completed WebS

An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent after a completed WebSocket handshake, dropping all active connections until the process restarts. This vulnerability is addressed in swift-nio version 2.101.0.

NVD description · AI analysis pending
5.3<1%
  • apple swiftnio
CVE-2026-65341
+1 in the same advisory: …65351
The issue was addressed with improved memory handling.

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption.

NVD description · AI analysis pending
5.4
group max
<1%
  • apple safari
  • apple ipados
  • apple iphone os
  • +1 more
CVE-2026-65346
+3 in the same advisory: …65343 …65349 …65347
An integer overflow was addressed with improved input validation.

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing an image may lead to arbitrary code execution.

NVD description · AI analysis pending
8.8
group max
<1%
  • apple ipados
  • apple iphone os
  • apple macos