Apple Updates Everything, (Mon, Sep 14th)
Apple patched a record 261 vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS 27, and other platforms, with none flagged as exploited.
Apple's annual OS update shipped iOS/iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27, and visionOS 27 plus bug-fix releases for the 26 and 15 branches, fixing a record 261 vulnerabilities. Notable issues include multiple kernel flaws allowing root privilege escalation (CVE-2026-43689, CVE-2026-43691, CVE-2026-43698, CVE-2026-43786), remote code execution in CUPS (CVE-2026-43692), kernel memory corruption via malicious NFS servers (CVE-2026-43686, CVE-2026-43687), and WebKit memory corruption from crafted web content (CVE-2026-43715). No vulnerabilities are labeled as actively exploited, and Apple does not assign per-CVE severities. Users report iOS 26.7 being downloaded when iOS 27 is intended, and tools like Little Snitch and BlockBlock need updates before upgrading to macOS 27.
- Record 261 vulnerabilities patched across all Apple operating systems
- No vulnerabilities flagged as actively exploited in the wild
- Kernel root privilege escalations and remote CUPS code execution included
- Third-party tools like Little Snitch require updates before macOS 27 upgrade
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-3437 | A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial of service (DoS) attack. NVD description · AI analysis pending | 6.5 | 4% |
| — | ||
| CVE-2026-20683 | Sign In With Apple Auth Flaw Exposes Apple Accounts on iOS, macOS, visionOS CVE-2026-20683 is an authentication weakness in Apple's Sign In With Apple flow caused by improper state management, allowing an app on the device to abuse the authentication flow and gain access to the user's Apple Account. Exploitation requires a malicious or vulnerable app already present on an affected iPhone, iPad, Mac, or Vision Pro; no separate network exposure is needed. A successful attacker could potentially access the victim's Apple Account, which typically gates iCloud data, purchases, and linked services. The flaw affects devices running iOS/iPadOS versions prior to 27, macOS prior to Sequoia 15.8 / Tahoe 26.7 / Golden Gate 27, and visionOS prior to 27, all fixed in Apple's September 2025 release wave. No public proof-of-concept or in-the-wild exploitation has been reported, and the issue is not on the CISA KEV list. Do: Update all Apple devices immediately to iOS 27 / iPadOS 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, or visionOS 27, and use MDM or Apple's rapid security response tooling to force fleet-wide patching. Review the list of apps authorized to use Sign In With Apple (Settings > Apple Account > Sign-In and Security) and revoke access for any untrusted or unknown third-party apps. Audit enterprise app inventories for apps that initiate Sign In With Apple flows, since a malicious app on the device is the delivery vector. | — | — |
| mass≈1-2 billion Apple devices potentially exposed until patched (Apple's active install base exceeds 2 billion devices) | ||
| CVE-2026-28899 | Gatekeeper bypass in Apple macOS Sequoia, Tahoe, and Golden Gate CVE-2026-28899 is a logic flaw in Apple's Gatekeeper security mechanism on macOS that allows a malicious app to bypass Gatekeeper's validation checks. Gatekeeper normally verifies that downloaded apps are notarized and signed before allowing them to run; a bypass means an attacker-controlled app downloaded to a victim's Mac could execute without passing those checks or triggering the standard user-approval flow. Successful exploitation gives an attacker a way to launch untrusted code on target machines, which is typically used as an initial-access step that is chained with other flaws to escape sandboxes or gain elevated privileges. All Macs running macOS Sequoia before 15.8, macOS Tahoe before 26.6, and macOS Golden Gate before 27 are affected; Apple addressed the issue with improved checks in its September 14 broad software update. As of the available data, there is no public proof-of-concept, no CVSS score, and no evidence of in-the-wild exploitation. Do: Update affected Macs immediately: macOS Sequoia to 15.8, macOS Tahoe to 26.6 or 26.7, or macOS Golden Gate to 27 via System Settings > Software Update. On managed fleets, verify patch compliance and confirm Gatekeeper is enabled (e.g., `spctl --status` reports assessments enabled). Gatekeeper bypasses are commonly chained with browser exploits and sandbox escapes, so treat rapid patching as high priority and monitor Apple's security advisories for follow-on CVEs. | — | — |
| massOrder of 100 million+ Macs (roughly 10^8), shrinking as users patch | ||
| CVE-2026-28930 | A permissions issue was addressed with additional restrictions. A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.5. An app may be able to access protected user data. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2026-43692 | Input Validation RCE Flaw in Apple macOS (Sequoia, Tahoe, Golden Gate) CVE-2026-43692 is an input validation and sanitization weakness in Apple's macOS that allows a remote attacker to cause unexpected application termination or execute arbitrary code on an affected Mac. The exact component and attack vector were not specified in the advisory, but flaws of this class are typically triggered by tricking a target into processing maliciously crafted content or input, and exploitation would let an attacker crash apps or run code in the context of the vulnerable process. All Macs running macOS Sequoia before 15.8, macOS Tahoe before 26.7, or macOS Golden Gate before 27 are affected; Apple patched the issue in those releases, which shipped alongside the company's broad September security updates. The vulnerability has no CVSS score yet, no public proof-of-concept is known, and it is not listed in CISA's Known Exploited Vulnerabilities catalog, indicating no observed in-the-wild exploitation at this time. Do: Update affected Macs immediately to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27 (or later) via System Settings > Software Update, and prioritize the update in MDM/patch management since arbitrary code execution flaws in macOS are prime targets once details emerge. There is no published workaround, so patching is the primary mitigation. After patching, monitor Apple's security advisory and threat intel feeds for the affected component and any emerging exploitation before this CVE receives a CVSS score. | 8.8 group max | — |
| massPotentially hundreds of millions of Macs; Apple's active Mac installed base is commonly estimated at well over 100 million devices, most running the affected… | ||
| CVE-2026-28935 | Kernel Memory Corruption in Apple iOS, iPadOS, macOS, tvOS, visionOS, watchOS CVE-2026-28935 is a kernel memory-handling flaw affecting Apple's operating systems across iPhone, iPad, Mac, Apple TV, Apple Watch, and Apple Vision Pro. A malicious or compromised app running on an affected device may be able to corrupt kernel memory or cause unexpected system termination (crash/DoS), and kernel memory corruption issues of this class can potentially be leveraged to escape app sandboxing or elevate privileges, though Apple's advisory only confirms corruption and termination. Exploitation requires local code execution — an attacker must first get a victim to install and run a malicious app, or compromise an already-installed app. Apple addressed the issue with improved memory handling in iOS 26.6.1, iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, and watchOS 27. No public proof of concept is known, the flaw is not on the CISA KEV list, and there are no reports of in-the-wild exploitation. Do: Patch all Apple devices promptly: iOS/iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, and watchOS 27 (paired iPhone updates are required to update watchOS). Enable automatic updates and verify patch levels across managed device fleets via MDM. Because the flaw is triggered by a local app, restrict sideloading and untrusted third-party app sources and review recently installed apps for suspicious behavior until devices are patched. | — | — |
| massPotentially hundreds of millions to over 1 billion devices (Apple's ~2 billion active devices minus those already updated) | ||
| CVE-2026-28937 | App-Mediated Sensitive Data Access Flaw in Apple macOS (Fixed in macOS Golden Gate 27) CVE-2026-28937 is a state-management flaw in Apple macOS that can allow an app running on a Mac to access sensitive user data that it should not be permitted to read. The issue is triggered locally: an attacker would need to get a malicious app onto the victim's machine, or abuse an already-installed app, rather than attacking the system remotely over a network. Successful abuse results in unauthorized access to sensitive user information — a privacy/information-disclosure impact — not remote code execution. The flaw affects Macs running macOS versions prior to the fix; Apple addressed it through improved state management and shipped the patch in macOS Golden Gate 27 as part of a broad September software update. CVSS has not yet been scored, no public proof-of-concept is known, and the issue is not listed in CISA's Known Exploited Vulnerabilities catalog. Do: Update to macOS Golden Gate 27 or later via System Settings > General > Software Update as soon as possible, and have IT admins expedite deployment across managed Mac fleets. Because the flaw is app-mediated, review and restrict permissions granted to third-party apps and avoid installing untrusted software. No configuration workaround is documented, so patching is the primary mitigation. | 5.5 | — |
| masson the order of 100 million+ Mac users, shrinking as users adopt macOS Golden Gate 27 | ||
| CVE-2026-28966 +1 in the same advisory: …28968 | Out-of-Bounds Write in Apple iOS, iPadOS, macOS, tvOS, and visionOS CVE-2026-28966 is an out-of-bounds write flaw caused by insufficient bounds checking in Apple's operating systems, patched across iOS/iPadOS, macOS, tvOS, and visionOS. It is triggered when a device processes a maliciously crafted file, meaning an attacker needs to deliver a booby-trapped file to the target (e.g., via a message, download, or web content). Apple's stated impact is unexpected app termination (a denial-of-service condition), though out-of-bounds writes are a memory-corruption class that can potentially be escalated to arbitrary code execution depending on the affected component. All users on iOS/iPadOS prior to 26.7 or 27, macOS Sequoia prior to 15.8, macOS Tahoe prior to 26.7, macOS Golden Gate prior to 27, tvOS prior to 27, and visionOS prior to 27 are affected. No CVSS score has been assigned, the flaw is not on the CISA KEV list, and no public proof-of-concept or in-the-wild exploitation is known. Do: Update all Apple devices promptly: iPhone/iPad to iOS/iPadOS 26.7 or 27, Macs to macOS Sequoia 15.8, Tahoe 26.7, or Golden Gate 27, Apple TV to tvOS 27, and Vision Pro to visionOS 27 (Settings > General > Software Update). Enable automatic updates and use MDM to force patch deployment across managed fleets. Treat unsolicited files, attachments, and media from untrusted sources with caution until patched, since the flaw is triggered by processing a maliciously crafted file. | — | — |
| mass≈1B+ devices (essentially the entire Apple iPhone, iPad, Mac, Apple TV, and Vision Pro installed base not yet patched) | ||
| CVE-2026-43661 +1 in the same advisory: …28969 | A buffer overflow issue was addressed with improved memory handling. A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, iOS 26.7 and iPadOS 26.7, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. Processing a maliciously crafted image may corrupt process memory. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2026-34979 | OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, there is a heap-based buffer overflow in the CUPS scheduler when building filter option strings from job attribute. At time of publication, there are no publicly available patches. NVD description · AI analysis pending | 5.3 | <1% | PoC |
| — | |
| CVE-2026-43684 | Kernel Use-After-Free in Apple iOS, iPadOS, and macOS CVE-2026-43684 is a use-after-free vulnerability in Apple's kernel memory management affecting iOS, iPadOS, and macOS. The flaw is triggered by an app running on the device: a malicious or already-compromised app may be able to cause unexpected system termination or corrupt kernel memory. Kernel memory corruption of this class is significant because it can potentially be developed into a privilege-escalation or sandbox-escape primitive, though Apple's advisory describes only termination and corruption as the impact. Users on iOS and iPadOS versions prior to 26.7, macOS Sequoia prior to 15.8, and macOS Golden Gate prior to 27 are affected, with fixes shipped in iOS/iPadOS 26.7, macOS Sequoia 15.8, and macOS Golden Gate 27. No public proof-of-concept is known and there is no indication of in-the-wild exploitation at this time. Do: Patch iPhones and iPads to iOS/iPadOS 26.7 and Macs to macOS Sequoia 15.8 or macOS Golden Gate 27, pushing the updates via MDM on managed fleets as a priority. Because exploitation requires a malicious or already-compromised app on the device, audit installed apps and restrict sideloading or non-App Store software on high-value endpoints. Monitor Apple's security advisory for researcher credit and any added exploitation notes, since kernel use-after-free bugs are common building blocks in full exploit chains and should not sit unpatched. | 7.8 group max | — |
| massHundreds of millions of unpatched iPhones, iPads, and Macs (order of magnitude: 10^8+ devices) | ||
| CVE-2026-43674 | Authentication Bypass Lets Physical Attacker View Wi-Fi Passwords on iOS/iPadOS CVE-2026-43674 is an authentication flaw in Apple's iOS and iPadOS caused by improper state management in the handling of sensitive settings. It is triggered when an attacker has physical access to a device that is already unlocked, allowing them to view saved Wi-Fi passwords without passing any additional authentication prompt. Successful abuse reveals stored Wi-Fi network credentials, which an attacker could reuse to join and position themselves on those networks for further attacks. The issue is fixed in iOS 27 and iPadOS 27, meaning devices running earlier releases remain exposed. No public proof-of-concept exists, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported. Do: Update iPhones and iPads to iOS 27 or iPadOS 27 as soon as rollout reaches your devices, and prioritize shared or helpdesk-managed devices. Because exploitation requires physical access to an unlocked device, require immediate auto-lock with short timeouts and avoid leaving unlocked devices unattended or handing them to untrusted parties. Administrators should audit managed-device update compliance and treat leaked Wi-Fi credentials as rotatable secrets if devices were exposed. | — | — |
| massPotentially hundreds of millions to over 1 billion iPhone/iPad users (devices not yet updated to iOS/iPadOS 27) | ||
| CVE-2026-43683 +1 in the same advisory: …43697 | Out-of-Bounds Read in Apple macOS Could Leak Process Memory CVE-2026-43683 is an out-of-bounds read in Apple's macOS that was fixed with improved bounds checking. A malicious or compromised app running on an affected Mac can trigger the flaw to cause unexpected process termination (a crash) or to disclose process memory, potentially exposing sensitive data held in that process such as tokens or other secrets. The flaw affects macOS Sequoia prior to 15.8, macOS Tahoe prior to 26.7, and macOS Golden Gate prior to 27, with fixes shipping in Apple's broad September 14 'Updates Everything' release wave. No CVSS score has been assigned yet, no public proof of concept exists, and there is no evidence of exploitation in the wild. Do: Update to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27 (or later) via System Settings > General > Software Update. Since exploitation requires a malicious app on the Mac, enforce Gatekeeper/notarization policies and restrict software installs to trusted sources. On managed fleets, audit recently added third-party apps and confirm patch compliance against Apple's September security advisory. | — | — |
| mass≈100M+ devices (active Macs running unpatched Sequoia/Tahoe/Golden Gate) | ||
| CVE-2026-43686 | Kernel Use-After-Free in Apple NFS Client Across iOS, macOS, and watchOS CVE-2026-43686 is a use-after-free vulnerability in Apple's kernel NFS client, disclosed in Apple's September 2026 mass update. It is triggered when a device connects to (mounts a share from) a malicious NFS server, which can lead to kernel memory corruption — typically enough to crash the device or potentially execute code with kernel privileges. All unpatched iPhones, iPads, Macs, Apple TVs, Vision Pro headsets, and Apple Watches are affected, though practical exploitation requires the target to actually connect to an attacker-controlled NFS server, which is uncommon for consumers and mostly plausible in enterprise/managed-network or automount scenarios. No CVSS score has been assigned, no public proof-of-concept is known, and the flaw is not in the CISA KEV catalog, with no reports of in-the-wild exploitation. The issue was fixed with improved memory management in the September 2026 OS releases. Do: Patch to the fixed releases: iOS/iPadOS 26.7 or 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27. Users and admins should avoid mounting NFS shares from untrusted networks or unknown servers, and enterprise teams should audit automount/NFS configuration profiles so managed devices only connect to vetted NFS infrastructure. Watch for a CVSS score and any follow-on advisory, since kernel memory corruption flaws in Apple platforms are frequently combined with other bugs in chained attacks. | 8.8 | — |
| mass≈1–2 billion active Apple devices potentially affected, but the practically exploitable subset (devices mounting NFS shares) is far smaller | ||
| CVE-2026-43688 | Memory Corruption from Malicious File in Apple iOS, iPadOS, and macOS Golden Gate CVE-2026-43688 is a memory corruption vulnerability in Apple's operating systems caused by insufficient input validation during file processing. It is triggered when a device processes a maliciously crafted file, and Apple's advisory lists unexpected app termination (denial of service) as the observed impact, though memory corruption flaws carry inherent risk of worse outcomes depending on the underlying defect. The issue was fixed with improved input validation in iOS 27, iPadOS 27, and macOS Golden Gate 27, meaning all iPhones, iPads, and Macs running earlier releases are affected. No CVSS score has been assigned yet, and there is no known public proof of concept or evidence of in-the-wild exploitation. Do: Update iPhones and iPads to iOS/iPadOS 27 and Macs to macOS Golden Gate 27 or later as soon as the September updates are available. Until devices are patched, advise users to avoid opening files, attachments, or downloads from untrusted or unexpected sources, since the flaw is triggered simply by processing a maliciously crafted file. Monitor for a CVSS assignment and any CISA KEV listing, which would signal elevated active-exploitation risk. | — | — |
| mass≈1 billion+ iPhone/iPad users plus 100 million+ Macs not yet on the 27 releases (order-of-magnitude estimate) | ||
| CVE-2026-43690 | Race condition allows local kernel memory read in Apple macOS CVE-2026-43690 is a race condition in Apple's macOS caused by insufficient locking, which Apple addressed with improved locking mechanics. A local attacker with an existing account on an affected Mac could exploit the timing flaw to read portions of kernel memory, potentially exposing sensitive data such as pointers, credentials, or secrets that could aid in further privilege-escalation or sandbox-escape chains. Only users on unpatched macOS versions are affected; the fix ships in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. The issue requires local access, so remote exploitation is not in scope. No public proof of concept is known and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog. Do: Patch affected Macs to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27 (or later) as soon as practical via Software Update or your MDM deployment. Because exploitation requires local access, enforce least-privilege local account policies, limit who can run arbitrary code on shared or lab Macs, and review logs for suspicious local privilege-elevation attempts. | — | — |
| masslikely tens to hundreds of millions of Macs (unpatched macOS installs) | ||
| CVE-2026-43695 | Authorization flaw in Apple OS permission handling lets apps read sensitive data CVE-2026-43695 is an authorization issue caused by improper state management in Apple's operating systems, fixed across iOS, iPadOS, macOS, tvOS, visionOS, and watchOS in the September 2026 updates. A malicious or poorly behaved app running on an unpatched device could exploit inconsistent permission state to access sensitive user data beyond what it was authorized to see. Exploitation requires a victim to run the attacker's app on an affected iPhone, iPad, Mac, Apple TV, Apple Watch, or Vision Pro; no user interaction with a remote attacker is implied. All users on versions prior to the fixed releases listed in Apple's advisory are affected. No public proof-of-concept exists, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported. Do: Patch all Apple devices to the fixed releases: iOS/iPadOS 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27. Enterprise admins should push these updates via MDM and prioritize them since the flaw allows apps to read sensitive user data. Users and defenders should also audit installed apps and review app permissions under Settings > Privacy & Security to remove any untrusted apps with broad data access. | — | — |
| masslikely hundreds of millions to over a billion devices (all unpatched Apple devices) | ||
| CVE-2026-43696 | Authorization Bypass in macOS Lets Apps Capture Touch Bar Content An authorization flaw in macOS, caused by insufficient entitlement checks, allows a locally installed app to capture Touch Bar content without the user's permission. A malicious or compromised app on an affected Mac could passively read whatever is displayed on the Touch Bar — which can include predictive-text suggestions and app-specific input — making this a keystroke-adjacent privacy leak rather than a remote attack. The issue is fixed in macOS Golden Gate 27 and affects Macs with Touch Bar hardware (2016–2019 MacBook Pro models) running earlier macOS versions. Exploitation requires the attacker to already run an app on the target Mac, so the practical risk is local snooping by untrusted software. No CVSS score has been assigned yet, there is no public proof of concept, no CISA KEV entry, and no known exploitation; the fix shipped in Apple's broad September update wave. Do: Upgrade all Touch Bar–equipped Macs to macOS Golden Gate 27 or later, and confirm which older units are eligible for the update, since Touch Bar hardware that cannot upgrade may remain exposed. Because exploitation requires a local app, audit installed software and screen-capture/TCC permission grants on these machines. Treat unpatched Touch Bar Macs as carrying a typed-input privacy risk and avoid running untrusted apps on them. | — | — |
| masstens of millions of Touch Bar–equipped Macs plausibly still in use (subset of Apple's 100M+ active Mac installed base) | ||
| CVE-2026-43698 | An injection issue was addressed with improved validation. An injection issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.7. An app may be able to gain root privileges. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2026-43702 | Video-Processing Memory Corruption in Apple iOS, iPadOS, macOS, tvOS, watchOS CVE-2026-43702 is a memory-handling flaw in Apple's operating systems that is triggered when a device processes a maliciously crafted video file. Successful exploitation can cause unexpected app termination (denial of service) or corruption of process memory, which in Apple's own disclosure language creates a memory-corruption condition in the media-handling path. The flaw affects iPhones, iPads, Macs (both macOS Sequoia and Tahoe), Apple TV, and Apple Watch, and was addressed with improved memory handling in Apple's September updates. There is no CVSS score yet, no public proof-of-concept, and no indication of in-the-wild exploitation. Users are exposed primarily through playing or previewing video files received from untrusted sources, such as messaging attachments or downloads. Do: Patch all Apple devices to the fixed releases: iOS/iPadOS 26.6 or 26.7, macOS Sequoia 15.8 or macOS Tahoe 26.6/26.7, tvOS 26.6, and watchOS 26.6, prioritizing via MDM in managed fleets. Instruct users to avoid opening or previewing video files from untrusted sources. Treat reports of apps crashing or behaving erratically during video playback as a potential indicator and verify OS versions fleet-wide. | — | — |
| massplausibly hundreds of millions of devices (Apple's installed base exceeds 1.5 billion active devices, most not yet on the 26.6/26.7/15.8 fix releases at… | ||
| CVE-2026-43715 | A use-after-free issue was addressed with improved memory management. A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, iOS 26.7 and iPadOS 26.7, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption. NVD description · AI analysis pending | 8.8 | <1% |
| — |
Full article3,301 words · extracted from isc.sans.edu · click to collapse
Today, Apple released its annual update across all its operating systems. With that, Apple not only released new features but also patched 261 different vulnerabilities. This is the most vulnerabilities Apple has ever patched, but the increase is not as significant as other vendors' "post-AI" patch releases.
In addition to the major "27" version, Apple also released bug-fix-only releases for the 26 branch of its operating systems and for 15 (Sequioa) for macOS. None of the vulnerabilities is labeled as being exploited. Apple does not note a severity to individual vulnerabilities.
There are some reports about difficulties downloading iOS 27. Users instead see 26.7 downloaded, but iOS 27 may actually be installed. Also note that some security-relevant applications, such as Little Snitch, have recently released updates that must be applied before upgrading to macOS 27. The Objective-See utility BlockBlock released version 2.5.2 to improve macOS 27 compatiblity.

Figure: Number of patches for each update over the last 2 years.
| iOS 27 and iPadOS 27 | iOS 26.7 and iPadOS 26.7 | macOS Golden Gate 27 | macOS Tahoe 26.7 | macOS Sequoia 15.8 | tvOS 27 | watchOS 27 | visionOS 27 |
|---|---|---|---|---|---|---|---|
| CVE-2022-3437: A user in a privileged network position may be able to leak sensitive user information. Affects Heimdal |
|||||||
| x | x | x | |||||
| CVE-2026-20683: An app may be able to use the Sign In With Apple authentication flow to access the user's Apple Account. Affects Apple Account |
|||||||
| x | x | x | x | x | |||
| CVE-2026-28899: An app may bypass Gatekeeper checks. Affects WebDAV |
|||||||
| x | x | x | |||||
| CVE-2026-28930: An app may be able to access protected user data. Affects Spotlight |
|||||||
| x | |||||||
| CVE-2026-28934: Mounting a malicious disk image may cause unexpected system termination. Affects HFS |
|||||||
| x | x | x | |||||
| CVE-2026-28935: An app may be able to cause unexpected system termination or corrupt kernel memory. Affects Kernel |
|||||||
| x | x | x | x | ||||
| CVE-2026-28937: An app may be able to access sensitive user data. Affects Terminal |
|||||||
| x | |||||||
| CVE-2026-28966: Processing a maliciously crafted file may lead to unexpected app termination. Affects RealityKit |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-28968: An app may be able to cause unexpected system termination or corrupt kernel memory. Affects Kernel |
|||||||
| x | x | x | x | x | x | x | x |
| CVE-2026-28969: An app may be able to cause unexpected system termination. Affects IOKit |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-34979: An attacker in a privileged network position may be able to cause a denial-of-service. Affects CUPS |
|||||||
| x | |||||||
| CVE-2026-43661: Processing a maliciously crafted image may corrupt process memory. Affects ImageIO |
|||||||
| x | |||||||
| CVE-2026-43664: An app may be able to access sensitive user data. Affects Accessibility |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-43674: An attacker with physical access to an unlocked device may be able to view Wi-Fi passwords without authentication. Affects Wi-Fi3 |
|||||||
| x | |||||||
| CVE-2026-43677: Connecting to a malicious WebDAV server may lead to unexpected app termination. Affects WebDAV |
|||||||
| x | x | x | |||||
| CVE-2026-43683: An app may be able to cause unexpected process termination or disclose process memory. Affects CoreDrag |
|||||||
| x | x | x | |||||
| CVE-2026-43684: An app may be able to cause unexpected system termination or corrupt kernel memory. Affects Kernel |
|||||||
| x | x | x | |||||
| CVE-2026-43686: Connecting to a malicious NFS server may lead to kernel memory corruption. Affects Kernel |
|||||||
| x | x | x | x | x | x | x | x |
| CVE-2026-43687: Connecting to a malicious NFS server may disclose kernel memory. Affects Kernel |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-43688: Processing a maliciously crafted file may lead to unexpected app termination. Affects Filters |
|||||||
| x | x | ||||||
| CVE-2026-43689: A malicious app may be able to gain root privileges. Affects Kernel |
|||||||
| x | x | x | x | ||||
| CVE-2026-43690: A local user may be able to read kernel memory. Affects SMB |
|||||||
| x | x | x | |||||
| CVE-2026-43691: An app may be able to gain root privileges. Affects CUPS |
|||||||
| x | x | x | |||||
| CVE-2026-43692: A remote user may cause an unexpected app termination or arbitrary code execution. Affects CUPS |
|||||||
| x | x | x | |||||
| CVE-2026-43695: An app may be able to access sensitive user data. Affects NetworkExtension |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-43696: An app may be able to capture Touch Bar content without authorization. Affects Touch Bar |
|||||||
| x | |||||||
| CVE-2026-43697: Processing a maliciously crafted 3D file may lead to an out-of-bounds read. Affects SceneKit |
|||||||
| x | x | x | |||||
| CVE-2026-43698: An app may be able to gain root privileges. Affects CUPS |
|||||||
| x | x | ||||||
| CVE-2026-43702: Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory. Affects CoreMedia Video Toolbox |
|||||||
| x | x | x | |||||
| CVE-2026-43715: Processing maliciously crafted web content may lead to memory corruption. Affects WebKit |
|||||||
| x | |||||||
| CVE-2026-43719: Mounting a maliciously crafted SMB network share may lead to system termination. Affects SMB |
|||||||
| x | x | x | |||||
| CVE-2026-43737: An app may be able to access motion data from headphones without user consent. Affects CoreMotion |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-43738: Processing a maliciously crafted asset catalog may result in disclosure of process memory. Affects CoreUI |
|||||||
| x | x | ||||||
| CVE-2026-43741: An app may be able to access protected user data. Affects Messages |
|||||||
| x | x | x | |||||
| CVE-2026-43743: An app may be able to cause unexpected system termination. Affects IOGPUFamily |
|||||||
| x | x | ||||||
| CVE-2026-43760: An app may be able to access user-sensitive data. Affects Screen Sharing Server |
|||||||
| x | |||||||
| CVE-2026-43763: An app may be able to read files outside of its sandbox. Affects ATS |
|||||||
| x | x | ||||||
| CVE-2026-43785: An app may be able to modify a file it only had permission to read. Affects File Bookmark |
|||||||
| x | x | x | x | x | x | ||
| CVE-2026-43786: An app may be able to gain root privileges. Affects CoreServices |
|||||||
| x | x | x | |||||
| CVE-2026-43787: An attacker in a privileged network position may be able to leak sensitive user information. Affects Mail |
|||||||
| x | x | x | |||||
| CVE-2026-43788: Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents. Affects Spotlight |
|||||||
| x | |||||||
| CVE-2026-43789: An app may be able to access user-sensitive data. Affects CoreMedia |
|||||||
| x | x | x | |||||
| CVE-2026-43790: A remote attacker may be able to cause unexpected system termination or corrupt kernel memory. Affects Kernel |
|||||||
| x | x | x | |||||
| CVE-2026-43791: An app may be able to read arbitrary files. Affects StorageKit |
|||||||
| x | x | x | |||||
| CVE-2026-43794: Processing maliciously crafted web content may lead to memory corruption. Affects WebKit |
|||||||
| x | x | x | |||||
| CVE-2026-64712: An app may be able to gain root privileges. Affects odproxyd |
|||||||
| x | x | x | |||||
| CVE-2026-64714: Processing a maliciously crafted image may lead to a denial-of-service. Affects ImageIO |
|||||||
| x | |||||||
| CVE-2026-64715: Processing maliciously crafted web content may lead to an unexpected process crash. Affects WebKit |
|||||||
| x | x | x | |||||
| CVE-2026-64718: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebKit Canvas |
|||||||
| x | x | x | x | ||||
| CVE-2026-64736: An app may be able to cause unexpected system termination or corrupt kernel memory. Affects IOMobileFrameBuffer |
|||||||
| x | x | x | x | ||||
| CVE-2026-64752: Processing a maliciously crafted image may lead to arbitrary code execution. Affects CoreMedia |
|||||||
| x | x | x | |||||
| CVE-2026-64753: Processing maliciously crafted web content may disclose sensitive user information. Affects WebKit |
|||||||
| x | x | x | x | x | |||
| CVE-2026-64756: An app may be able to access user-sensitive data. Affects Image Capture |
|||||||
| x | x | x | x | ||||
| CVE-2026-64758: Processing a maliciously crafted file may lead to unexpected app termination. Affects ImageIO |
|||||||
| x | x | ||||||
| CVE-2026-64760: An app may be able to leak sensitive kernel state. Affects IOSurfaceAccelerator |
|||||||
| x | x | x | x | x | |||
| CVE-2026-64761: An app may be able to identify what other apps a user has installed. Affects Accessibility |
|||||||
| x | |||||||
| CVE-2026-64778: Visiting a maliciously crafted website may leak sensitive data. Affects WebKit History |
|||||||
| x | x | x | |||||
| CVE-2026-64779: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebKit Storage |
|||||||
| x | |||||||
| CVE-2026-64780: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebKit |
|||||||
| x | |||||||
| CVE-2026-64781: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebKit |
|||||||
| x | |||||||
| CVE-2026-64782: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebKit |
|||||||
| x | |||||||
| CVE-2026-64784: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebKit |
|||||||
| x | |||||||
| CVE-2026-64787: Processing maliciously crafted web content may lead to an unexpected process termination. Affects WebKit |
|||||||
| x | x | x | |||||
| CVE-2026-64788: Processing maliciously crafted web content may lead to memory corruption. Affects IOGPUFamily |
|||||||
| x | x | ||||||
| CVE-2026-64790: An app may be able to gain elevated privileges. Affects CUPS |
|||||||
| x | x | x | |||||
| CVE-2026-65329: An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic. Affects Telephony |
|||||||
| x | |||||||
| CVE-2026-65331: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebKit |
|||||||
| x | |||||||
| CVE-2026-65334: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebKit |
|||||||
| x | |||||||
| CVE-2026-65338: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebKit |
|||||||
| x | |||||||
| CVE-2026-65339: An app may be able to leak sensitive user information. Affects Audio |
|||||||
| x | x | x | x | ||||
| CVE-2026-65341: Processing maliciously crafted web content may lead to memory corruption. Affects WebKit |
|||||||
| x | x | x | |||||
| CVE-2026-65342: An app may be able to access sensitive user data. Affects ATS |
|||||||
| x | x | x | |||||
| CVE-2026-65343: A remote attacker may be able to cause unexpected system termination. Affects Kernel |
|||||||
| x | x | x | |||||
| CVE-2026-65344: Processing a maliciously crafted video file may lead to unexpected app termination. Affects CoreMedia |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-65345: An app may be able to access user-sensitive data. Affects Storage |
|||||||
| x | x | x | x | x | |||
| CVE-2026-65346: Processing an image may lead to arbitrary code execution. Affects ImageIO |
|||||||
| x | x | x | x | ||||
| CVE-2026-65347: Processing an image may lead to a denial-of-service. Affects ImageIO |
|||||||
| x | x | x | |||||
| CVE-2026-65348: An app may be able to modify protected parts of the file system. Affects Storage |
|||||||
| x | x | x | x | x | |||
| CVE-2026-65349: An app may be able to cause unexpected system termination or read kernel memory. Affects Kernel |
|||||||
| x | x | x | x | ||||
| CVE-2026-65354: A malicious app may be able to break out of its sandbox. Affects iWork |
|||||||
| x | x | ||||||
| CVE-2026-65358: An app may be able to cause unexpected system termination. Affects Kernel |
|||||||
| x | x | x | x | x | x | ||
| CVE-2026-65359: A local user may be able to cause unexpected system termination or read kernel memory. Affects Kernel |
|||||||
| x | x | x | x | x | x | x | x |
| CVE-2026-65360: An app may be able to cause unexpected system termination. Affects Kernel |
|||||||
| x | |||||||
| CVE-2026-65361: An app may be able to access sensitive user data. Affects SoftwareUpdate |
|||||||
| x | x | x | |||||
| CVE-2026-65362: An app may be able to gain root privileges. Affects Disk Images |
|||||||
| x | x | x | |||||
| CVE-2026-65364: A remote attacker may be able to cause unexpected system termination. Affects Kernel |
|||||||
| x | x | x | |||||
| CVE-2026-65365: Connecting to a malicious SMB share may disclose kernel memory. Affects SMB |
|||||||
| x | x | x | |||||
| CVE-2026-65369: A malicious application may bypass Gatekeeper checks. Affects Kernel |
|||||||
| x | x | x | |||||
| CVE-2026-65371: An app may be able to disclose kernel memory. Affects Kernel |
|||||||
| x | |||||||
| CVE-2026-65374: Connecting to a malicious WebDAV server may result in code execution. Affects WebDAV |
|||||||
| x | x | x | |||||
| CVE-2026-65375: An app may be able to cause unexpected system termination. Affects WebDAV |
|||||||
| x | x | ||||||
| CVE-2026-65376: An app may be able to cause unexpected system termination. Affects SMB |
|||||||
| x | x | x | |||||
| CVE-2026-65377: An app may be able to cause unexpected system termination. Affects Kernel |
|||||||
| x | x | x | x | x | x | x | x |
| CVE-2026-65378: An app may be able to access sensitive user data. Affects Spotlight |
|||||||
| x | x | x | |||||
| CVE-2026-65380: An app may be able to access protected user data. Affects Sandbox |
|||||||
| x | |||||||
| CVE-2026-65381: A malicious app may be able to break out of its sandbox. Affects AppleMobileFileIntegrity |
|||||||
| x | x | x | |||||
| CVE-2026-65382: An app may be able to access sensitive user data. Affects LaunchServices |
|||||||
| x | x | x | |||||
| CVE-2026-65383: An app may bypass Gatekeeper checks. Affects System Settings |
|||||||
| x | |||||||
| CVE-2026-65390: Processing maliciously crafted web content may lead to memory corruption. Affects WebRTC |
|||||||
| x | x | x | |||||
| CVE-2026-65391: Processing maliciously crafted web content may lead to memory corruption. Affects WebRTC |
|||||||
| x | x | x | |||||
| CVE-2026-65393: An app may be able to access user-sensitive data. Affects Xcode IDE |
|||||||
| x | |||||||
| CVE-2026-65395: Processing a maliciously crafted image may result in memory corruption. Affects ImageIO |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-65398: An app may be able to cause unexpected system termination or corrupt kernel memory. Affects IOMobileFrameBuffer |
|||||||
| x | x | ||||||
| CVE-2026-65399: An archive may be able to bypass Gatekeeper. Affects copyfile |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-65400: An attacker on the network may be able to authenticate to Screen Sharing without valid credentials. Affects Screen Sharing Server |
|||||||
| x | x | ||||||
| CVE-2026-65401: An app may be able to cause unexpected system termination. Affects Kernel |
|||||||
| x | |||||||
| CVE-2026-65402: An app may be able to cause unexpected system termination. Affects Kernel |
|||||||
| x | x | x | x | x | |||
| CVE-2026-65403: An app may be able to access sensitive user data. Affects Reminders |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-65404: A malicious application may be able to bypass Privacy preferences. Affects Accounts |
|||||||
| x | x | ||||||
| CVE-2026-65405: An app may be able to determine kernel memory layout. Affects Kernel |
|||||||
| x | x | x | x | x | x | x | x |
| CVE-2026-65406: An app may be able to access sensitive user data. Affects BackgroundAssets |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-65407: An app may be able to cause unexpected system termination. Affects AppleAVD |
|||||||
| x | x | x | x | x | x | x | x |
| CVE-2026-65408: An app may be able to cause unexpected system termination. Affects Apple Neural Engine |
|||||||
| x | x | x | x | x | |||
| CVE-2026-65409: An app may be able to cause a denial of service. Affects Foundation |
|||||||
| x | x | x | x | x | x | x | x |
| CVE-2026-65410: An app may be able to cause unexpected system termination. Affects AVEVideoEncoder |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-65411: An app may be able to modify protected parts of the file system. Affects MobileBackup |
|||||||
| x | x | x | |||||
| CVE-2026-65412: Processing web content may lead to a denial-of-service. Affects CoreText |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-65413: An app may be able to cause a denial of service. Affects SceneKit |
|||||||
| x | x | x | |||||
| CVE-2026-65415: A local user may be able to cause unexpected system termination or read kernel memory. Affects Kernel |
|||||||
| x | x | x | x | x | |||
| CVE-2026-84487: Processing a maliciously crafted file may result in disclosure of process memory. Affects SceneKit |
|||||||
| x | x | x | x | x | x | x | x |
| CVE-2026-84489: An app may be able to cause a denial of service. Affects CoreUI |
|||||||
| x | x | ||||||
| CVE-2026-84491: An app may be able to access sensitive user data. Affects Photos Storage |
|||||||
| x | x | x | x | x | x | ||
| CVE-2026-84492: An app may be able to cause unexpected system termination. Affects Graphics |
|||||||
| x | x | x | x | x | x | x | x |
| CVE-2026-84497: Opening a maliciously crafted file may lead to unexpected process termination. Affects Model I/O |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-84505: An app may be able to gain root privileges. Affects Directory Utility |
|||||||
| x | x | x | |||||
| CVE-2026-84506: An app may be able to execute arbitrary code with kernel privileges. Affects udf |
|||||||
| x | x | x | |||||
| CVE-2026-84507: An app may be able to cause unexpected system termination or corrupt kernel memory. Affects Kernel |
|||||||
| x | x | x | x | x | x | x | x |
| CVE-2026-84509: Connecting to a malicious SMB server may lead to unexpected system termination. Affects SMB |
|||||||
| x | x | x | |||||
| CVE-2026-84510: Mounting a maliciously crafted volume may lead to unexpected system termination. Affects exFAT |
|||||||
| x | x | x | x | x | |||
| CVE-2026-84511: Processing a maliciously crafted asset catalog may lead to unexpected process termination. Affects CoreUI |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-84512: Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory. Affects Disk Images |
|||||||
| x | x | x | |||||
| CVE-2026-84513: A malicious application may be able to determine a user's current location. Affects Symptom Framework |
|||||||
| x | x | x | x | x | x | x | x |
| CVE-2026-84514: An app may be able to modify protected parts of the file system. Affects Kext Management |
|||||||
| x | x | x | |||||
| CVE-2026-84515: Connecting to a malicious SMB server may lead to kernel memory corruption. Affects SMB |
|||||||
| x | x | x | |||||
| CVE-2026-84516: Processing a maliciously crafted file may result in unexpected app termination or disclosure of process memory. Affects CUPS |
|||||||
| x | x | x | |||||
| CVE-2026-84517: An app may be able to cause unexpected system termination. Affects Kernel |
|||||||
| x | x | x | |||||
| CVE-2026-84518: A malicious website may be able to determine what apps a user has installed. Affects Safari |
|||||||
| x | x | ||||||
| CVE-2026-84519: Mounting a disk image with maliciously crafted files may lead to unexpected system termination. Affects AppleDouble |
|||||||
| x | x | x | x | x | |||
| CVE-2026-84520: A local attacker may be able to cause unexpected system termination or corrupt kernel memory. Affects AppleFDEKeyStore |
|||||||
| x | |||||||
| CVE-2026-84521: An app may be able to cause unexpected system termination. Affects Kernel |
|||||||
| x | x | x | |||||
| CVE-2026-84522: An app may be able to access sensitive user data. Affects Archive Utility |
|||||||
| x | |||||||
| CVE-2026-84523: An app may be able to cause unexpected system termination or write kernel memory. Affects APFS |
|||||||
| x | x | x | x | x | x | x | x |
| CVE-2026-84524: Processing a maliciously crafted font file may lead to unexpected app termination. Affects FontParser |
|||||||
| x | x | x | x | x | x | x | x |
| CVE-2026-84525: An app may be able to access user-sensitive data. Affects ATS |
|||||||
| x | x | x | |||||
| CVE-2026-84526: Processing a maliciously crafted 3D scene may lead to unexpected process termination. Affects SceneKit |
|||||||
| x | x | x | x | x | x | x | x |
| CVE-2026-84527: An app may be able to access sensitive user data. Affects TCC |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-84530: An app may be able to disclose kernel memory. Affects Kernel |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-84531: Processing maliciously crafted NTLM input may lead to unexpected app termination. Affects Security |
|||||||
| x | x | ||||||
| CVE-2026-84532: Opening a maliciously crafted file may cause unexpected process termination or disclose process memory. Affects RealityKit |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-84533: An attacker in a privileged network position may be able to modify network traffic. Affects Heimdal |
|||||||
| x | x | x | x | ||||
| CVE-2026-84534: Extracting a maliciously crafted archive may allow an attacker to write arbitrary files. Affects file_cmds |
|||||||
| x | x | x | x | x | x | ||
| CVE-2026-84535: An app may be able to break out of its sandbox. Affects Automator |
|||||||
| x | x | x | |||||
| CVE-2026-84536: Connecting to a malicious SMB server may lead to unexpected system termination. Affects SMB |
|||||||
| x | x | x | |||||
| CVE-2026-84537: An app may be able to cause unexpected system termination or corrupt kernel memory. Affects SMB |
|||||||
| x | x | x | |||||
| CVE-2026-84538: A remote attacker may be able to cause a denial-of-service. Affects Kernel |
|||||||
| x | x | x | |||||
| CVE-2026-84540: An app may be able to access sensitive user data. Affects CUPS |
|||||||
| x | x | x | |||||
| CVE-2026-84541: An application may be able to access restricted files. Affects CUPS |
|||||||
| x | x | x | |||||
| CVE-2026-84543: Connecting to a malicious SMB server may cause unexpected system termination or corrupt kernel memory. Affects SMB |
|||||||
| x | x | x | |||||
| CVE-2026-84544: Connecting to a malicious NFS server may cause unexpected system termination or corrupt kernel memory. Affects Kernel |
|||||||
| x | x | x | |||||
| CVE-2026-84548: Processing a maliciously crafted document may lead to an out-of-bounds read. Affects Quick Look |
|||||||
| x | x | x | |||||
| CVE-2026-84549: Connecting to a malicious NFS server may cause unexpected system termination or corrupt kernel memory. Affects Kernel |
|||||||
| x | x | x | |||||
| CVE-2026-84550: An app may be able to cause unexpected system termination. Affects Disk Images |
|||||||
| x | x | x | |||||
| CVE-2026-84551: An app may be able to bypass network restrictions. Affects Sandbox |
|||||||
| x | x | x | x | ||||
| CVE-2026-84552: An app may be able to cause unexpected system termination. Affects Disk Images |
|||||||
| x | x | x | x | x | |||
| CVE-2026-84553: A remote attacker may be able to cause a denial-of-service. Affects smbx |
|||||||
| x | x | x | |||||
| CVE-2026-84554: An attacker in a privileged network position may be able to cause a denial-of-service. Affects CUPS |
|||||||
| x | x | x | |||||
| CVE-2026-84555: An app may be able to access sensitive user data. Affects Sandbox |
|||||||
| x | x | ||||||
| CVE-2026-84556: An app may be able to access sensitive user data. Affects Keychain Access |
|||||||
| x | x | x | |||||
| CVE-2026-84558: An app may be able to cause unexpected system termination. Affects Kernel |
|||||||
| x | |||||||
| CVE-2026-84559: A malicious application may be able to access restricted files. Affects CoreServices |
|||||||
| x | x | x | |||||
| CVE-2026-84560: An app may gain unauthorized access to Bluetooth. Affects Bluetooth |
|||||||
| x | x | x | x | x | |||
| CVE-2026-84561: An app may be able to cause unexpected system termination or corrupt kernel memory. Affects Kernel |
|||||||
| x | x | x | x | x | x | x | x |
| CVE-2026-84563: An app may be able to cause unexpected system termination. Affects CUPS |
|||||||
| x | x | x | |||||
| CVE-2026-84564: Processing a maliciously crafted image may result in disclosure of process memory. Affects ImageIO |
|||||||
| x | x | x | x | x | x | x | x |
| CVE-2026-84565: Processing a maliciously crafted disk image may lead to unexpected app termination. Affects Disk Images |
|||||||
| x | x | x | |||||
| CVE-2026-84566: A local attacker may be able to cause unexpected system termination or corrupt kernel memory. Affects Kernel |
|||||||
| x | x | x | x | x | |||
| CVE-2026-84567: An app may be able to cause unexpected system termination. Affects cd9660 |
|||||||
| x | x | x | |||||
| CVE-2026-84568: An attacker with control of a network directory server may be able to execute arbitrary code with root privileges. Affects autofs |
|||||||
| x | x | x | |||||
| CVE-2026-84569: An app may be able to access sensitive user data. Affects Foundation |
|||||||
| x | |||||||
| CVE-2026-84570: An app may be able to bypass Gatekeeper checks. Affects autofs |
|||||||
| x | x | x | |||||
| CVE-2026-84571: Processing a maliciously crafted image may lead to unexpected app termination. Affects CoreUI |
|||||||
| x | x | x | x | x | |||
| CVE-2026-84572: An app may be able to cause unexpected system termination or read kernel memory. Affects udf |
|||||||
| x | x | x | |||||
| CVE-2026-84573: An app may be able to access sensitive user data. Affects Mail |
|||||||
| x | x | x | |||||
| CVE-2026-84574: An app may be able to bypass Privacy preferences. Affects CoreServices |
|||||||
| x | x | x | |||||
| CVE-2026-84575: Processing a maliciously crafted file may lead to unexpected app termination. Affects CoreUI |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-84576: An app may be able to access sensitive user data. Affects QuartzCore |
|||||||
| x | x | x | |||||
| CVE-2026-84577: An app may be able to bypass sandbox restrictions. Affects libxpc |
|||||||
| x | x | ||||||
| CVE-2026-84578: An app may be able to break out of its sandbox. Affects quarantine |
|||||||
| x | x | x | |||||
| CVE-2026-84580: An app may be able to break out of its sandbox. Affects quarantine |
|||||||
| x | x | x | |||||
| CVE-2026-84581: Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory. Affects HFS |
|||||||
| x | x | x | |||||
| CVE-2026-84583: A local app may be able to read a persistent account identifier. Affects AuthKit |
|||||||
| x | x | x | x | x | x | x | x |
| CVE-2026-84584: An app may be able to break out of its sandbox. Affects Archive Utility |
|||||||
| x | |||||||
| CVE-2026-84585: An app may be able to access local network devices without user consent. Affects NetworkExtension |
|||||||
| x | |||||||
| CVE-2026-84586: A malicious application may be able to leak sensitive user information. Affects Apple Account |
|||||||
| x | x | ||||||
| CVE-2026-84587: An app may be able to access protected user data. Affects AppKit |
|||||||
| x | x | x | |||||
| CVE-2026-84588: Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory. Affects Kernel |
|||||||
| x | |||||||
| CVE-2026-84589: An app may be able to modify Privacy preferences. Affects TCC |
|||||||
| x | |||||||
| CVE-2026-84593: An app may be able to cause unexpected system termination. Affects AppleKeyStore |
|||||||
| x | |||||||
| CVE-2026-84596: Processing a maliciously crafted font may result in the disclosure of process memory. Affects CoreText |
|||||||
| x | x | x | x | x | |||
| CVE-2026-84597: Processing a maliciously crafted font may result in the disclosure of process memory. Affects FontParser |
|||||||
| x | x | x | x | x | |||
| CVE-2026-84598: An attacker with physical access to a trust-paired device may be able to read and write arbitrary files. Affects MobileBackup |
|||||||
| x | x | ||||||
| CVE-2026-84600: A malicious shortcut may be able to send messages without user confirmation. Affects Shortcuts |
|||||||
| x | x | x | x | x | |||
| CVE-2026-84601: An app may be able to bypass Apple Intelligence security prompts. Affects Apple Intelligence |
|||||||
| x | |||||||
| CVE-2026-84602: An app may be able to cause unexpected system termination. Affects Kernel |
|||||||
| x | x | x | x | x | x | x | x |
| CVE-2026-84603: An app may be able to access sensitive user data. Affects Sandbox Profiles |
|||||||
| x | x | x | |||||
| CVE-2026-84606: An app may be able to identify a user across reinstalls. Affects iCloud |
|||||||
| x | x | x | |||||
| CVE-2026-84607: A sandboxed app may be able to execute arbitrary code with kernel privileges. Affects AVEVideoEncoder |
|||||||
| x | x | x | x | x | x | x | x |
| CVE-2026-84609: An app may be able to modify protected system files. Affects Software Update |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-84611: Processing a maliciously crafted 3D model may lead to memory corruption. Affects SceneKit |
|||||||
| x | x | x | x | x | x | x | x |
| CVE-2026-84612: An app may be able to read persistent device identifiers. Affects DeviceCheck |
|||||||
| x | x | x | x | x | x | x | x |
| CVE-2026-84615: An app may be able to access sensitive user data. Affects Music |
|||||||
| x | x | x | x | ||||
| CVE-2026-84616: An app may be able to cause unexpected system termination. Affects AVEVideoEncoder |
|||||||
| x | x | x | x | x | x | x | x |
| CVE-2026-84617: An app may be able to access sensitive user data. Affects XPC |
|||||||
| x | x | x | x | x | x | ||
| CVE-2026-84618: An app may be able to access sensitive user data. Affects Game Center |
|||||||
| x | x | x | |||||
| CVE-2026-84619: An app may be able to cause unexpected system termination or write kernel memory. Affects Kernel |
|||||||
| x | x | x | |||||
| CVE-2026-84620: Processing a maliciously crafted 3D model may lead to memory corruption. Affects SceneKit |
|||||||
| x | x | x | x | x | x | x | x |
| CVE-2026-84621: An app may be able to access sensitive user data. Affects Spotlight |
|||||||
| x | x | x | x | x | |||
| CVE-2026-84622: An app with root privileges may be able to read uninitialized kernel memory. Affects Kernel |
|||||||
| x | x | x | x | x | x | x | x |
| CVE-2026-84623: An app may be able to fingerprint the device. Affects Power Management |
|||||||
| x | x | ||||||
| CVE-2026-84624: A sandboxed app may be able to access restricted files. Affects CoreML |
|||||||
| x | x | x | x | x | x | ||
| CVE-2026-84625: An app may be able to fingerprint the user. Affects Sandbox Profiles |
|||||||
| x | x | x | x | ||||
| CVE-2026-84626: An app may be able to identify what other apps a user has installed. Affects NetworkExtension |
|||||||
| x | x | x | x | x | x | x | x |
| CVE-2026-84628: A sandboxed app may be able to access the System Keychain. Affects MediaRemote |
|||||||
| x | x | x | x | x | |||
| CVE-2026-84629: An app may be able to fingerprint the user. Affects Photos Storage |
|||||||
| x | x | x | x | ||||
| CVE-2026-84631: An app may be able to gain root privileges. Affects Bluetooth |
|||||||
| x | |||||||
| CVE-2026-84632: Processing a maliciously crafted 3D model may lead to memory corruption. Affects SceneKit |
|||||||
| x | x | x | x | x | x | x | x |
| CVE-2026-84635: Processing maliciously crafted web content may lead to an unexpected process termination. Affects WebKit |
|||||||
| x | x | x | x | x | |||
| CVE-2026-84636: An app may be able to access sensitive user data. Affects Wi-Fi Connectivity |
|||||||
| x | x | x | x | ||||
| CVE-2026-86869: Processing a maliciously crafted image may lead to unexpected app termination. Affects ImageIO |
|||||||
| x | x | ||||||
| CVE-2026-86870: Processing a maliciously crafted file may lead to unexpected app termination. Affects libarchive |
|||||||
| x | x | x | x | x | |||
| CVE-2026-86876: A sandboxed process may be able to circumvent sandbox restrictions. Affects CoreMedia |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-86878: An app may be able to access sensitive user data. Affects Camera |
|||||||
| x | |||||||
| CVE-2026-86879: A remote attacker may be able to cause a denial-of-service. Affects Baseband |
|||||||
| x | |||||||
| CVE-2026-86881: An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages. Affects Security |
|||||||
| x | x | x | x | x | x | x | x |
| CVE-2026-86882: Processing a maliciously crafted image may lead to unexpected process termination. Affects Accelerate Framework |
|||||||
| x | x | x | x | x | x | x | x |
| CVE-2026-86883: An app may be able to access sensitive user data. Affects Managed Configuration |
|||||||
| x | x | ||||||
| CVE-2026-86884: An app may be able to access sensitive user data. Affects Siri |
|||||||
| x | x | x | x | ||||
| CVE-2026-86885: An attacker in radio range may be able to cause unexpected system termination. Affects Baseband |
|||||||
| x | |||||||
| CVE-2026-86886: An app may be able to modify protected system files. Affects TCC |
|||||||
| x | x | x | |||||
| CVE-2026-86887: An app may be able to bypass certain Privacy preferences. Affects Time Zone |
|||||||
| x | x | x | |||||
| CVE-2026-86888: A local app may be able to read a persistent account identifier. Affects App Store |
|||||||
| x | x | x | x | x | x | ||
| CVE-2026-86889: An attacker in a privileged network position may be able to intercept network traffic. Affects Security |
|||||||
| x | x | x | |||||
| CVE-2026-86890: An attacker with physical access to a locked device may be able to view sensitive user information. Affects Siri Suggestions |
|||||||
| x | x | ||||||
| CVE-2026-86891: An app may be able to access Bluetooth device information. Affects Core Bluetooth |
|||||||
| x | x | x | x | ||||
| CVE-2026-86892: An app may be able to cause a denial-of-service. Affects SpringBoard |
|||||||
| x | x | x | |||||
| CVE-2026-86893: An app may be able to read device name. Affects CloudKit |
|||||||
| x | x | x | x | ||||
| CVE-2026-86894: An app may be able to break out of its sandbox. Affects libxpc |
|||||||
| x | |||||||
| CVE-2026-86895: A local app may be able to read a persistent account identifier. Affects CloudKit |
|||||||
| x | x | x | x | ||||
| CVE-2026-86897: An app may be able to access sensitive user data. Affects Safe Browsing |
|||||||
| x | x | x | x | ||||
| CVE-2026-86898: Opening a maliciously crafted webarchive file may lead to universal cross-site scripting. Affects WebKit |
|||||||
| x | x | x | |||||
| CVE-2026-86900: Mounting a maliciously crafted exFAT volume may cause unexpected system termination or kernel memory disclosure. Affects exFAT |
|||||||
| x | |||||||
| CVE-2026-86901: Mounting a maliciously crafted exFAT volume may cause unexpected system termination or kernel memory disclosure. Affects exFAT |
|||||||
| x | |||||||
| CVE-2026-86902: An app may be able to access sensitive user data. Affects NSDocument |
|||||||
| x | |||||||
| CVE-2026-86903: An app may be able to disclose kernel memory. Affects Kernel |
|||||||
| x | x | x | x | x | |||
| CVE-2026-86904: An app may be able to track users across apps and websites without permission. Affects Watch App |
|||||||
| x | x | x | |||||
| CVE-2026-86905: An app may be able to delete credentials stored in Keychain. Affects Authentication Services |
|||||||
| x | x | x | |||||
| CVE-2026-86909: An app may be able to bypass Gatekeeper checks. Affects System Settings |
|||||||
| x | |||||||
| CVE-2026-86910: An application may be able to access restricted files. Affects APFS |
|||||||
| x | x | x | |||||
| CVE-2026-86911: A malicious app may be able to bypass clickjacking protections for secure prompts. Affects Foundation |
|||||||
| x | |||||||
| CVE-2026-86917: An app may be able to gain root privileges. Affects Kernel |
|||||||
| x | x | x | |||||
| CVE-2026-86924: Connecting a malicious accessory may cause unexpected system termination. Affects MobileAccessoryUpdater |
|||||||
| x | x | x | x | ||||
--
Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu
Twitter|
Text extracted automatically; images, tables and formatting may be missing. Original: https://isc.sans.edu/diary/rss/33336