| CVE-2026-65400 |
Screen Sharing Server |
An attacker on the network may be able to authenticate to Screen Sharing without valid credentials |
9.8 | ⚠ KEV CRITICAL |
No | No | Yes | Yes | No | No | No | No | No | No |
| CVE-2026-65414 |
Bluetooth |
A remote attacker may be able to cause unexpected app termination or arbitrary code execution |
9.8 | CRITICAL |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-43692 |
CUPS |
A remote user may cause an unexpected app termination or arbitrary code execution |
8.8 | HIGH |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-65346 |
ImageIO |
Processing an image may lead to arbitrary code execution |
8.8 | HIGH |
No | No | No | No | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-43686 |
Kernel |
Connecting to a malicious NFS server may lead to kernel memory corruption |
8.8 | HIGH |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-65374 |
WebDAV |
Connecting to a malicious WebDAV server may result in code execution |
8.8 | HIGH |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-43715 |
WebKit |
Processing maliciously crafted web content may lead to memory corruption |
8.8 | HIGH |
No | Yes | No | No | No | No | No | No | No | No |
| CVE-2026-43794 |
WebKit |
Processing maliciously crafted web content may lead to memory corruption |
8.8 | HIGH |
No | No | No | No | No | Yes | Yes | Yes | No | No |
| CVE-2026-65390 |
WebRTC |
Processing maliciously crafted web content may lead to memory corruption |
8.8 | HIGH |
No | No | No | No | No | Yes | Yes | Yes | No | No |
| CVE-2026-65391 |
WebRTC |
Processing maliciously crafted web content may lead to memory corruption |
8.8 | HIGH |
No | No | No | No | No | Yes | Yes | Yes | No | No |
| CVE-2026-43760 |
Screen Sharing Server |
An app may be able to access user-sensitive data |
8.6 | HIGH |
No | No | No | Yes | No | No | No | No | No | No |
| CVE-2026-84581 |
HFS |
Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory |
8.4 | HIGH |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84535 |
Automator |
An app may be able to break out of its sandbox |
8.2 | HIGH |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84516 |
CUPS |
Processing a maliciously crafted file may result in unexpected app termination or disclosure of process memory |
8.1 | HIGH |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-65415 |
Kernel |
A local user may be able to cause unexpected system termination or read kernel memory |
8.1 | HIGH |
Yes | No | Yes | No | No | Yes | Yes | Yes | No | No |
| CVE-2026-84568 |
autofs |
An attacker with control of a network directory server may be able to execute arbitrary code with root privileges |
7.8 | HIGH |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84607 |
AVEVideoEncoder |
A sandboxed app may be able to execute arbitrary code with kernel privileges |
7.8 | HIGH |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-84631 |
Bluetooth |
An app may be able to gain root privileges |
7.8 | HIGH |
No | No | Yes | No | No | No | No | No | No | No |
| CVE-2026-43786 |
CoreServices |
An app may be able to gain root privileges |
7.8 | HIGH |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84575 |
CoreUI |
Processing a maliciously crafted file may lead to unexpected app termination |
7.8 | HIGH |
Yes | No | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-43691 |
CUPS |
An app may be able to gain root privileges |
7.8 | HIGH |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-43698 |
CUPS |
An app may be able to gain root privileges |
7.8 | HIGH |
No | No | Yes | Yes | No | No | No | No | No | No |
| CVE-2026-84505 |
Directory Utility |
An app may be able to gain root privileges |
7.8 | HIGH |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-65362 |
Disk Images |
An app may be able to gain root privileges |
7.8 | HIGH |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-64758 |
ImageIO |
Processing a maliciously crafted file may lead to unexpected app termination |
7.8 | HIGH |
No | Yes | No | No | Yes | No | No | No | No | No |
| CVE-2026-43684 |
Kernel |
An app may be able to cause unexpected system termination or corrupt kernel memory |
7.8 | HIGH |
No | Yes | Yes | No | Yes | No | No | No | No | No |
| CVE-2026-43689 |
Kernel |
A malicious app may be able to gain root privileges |
7.8 | HIGH |
Yes | Yes | Yes | No | No | No | No | Yes | No | No |
| CVE-2026-86917 |
Kernel |
An app may be able to gain root privileges |
7.8 | HIGH |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-64712 |
odproxyd |
An app may be able to gain root privileges |
7.8 | HIGH |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84515 |
SMB |
Connecting to a malicious SMB server may lead to kernel memory corruption |
7.8 | HIGH |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84506 |
udf |
An app may be able to execute arbitrary code with kernel privileges |
7.8 | HIGH |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-64761 |
Accessibility |
An app may be able to identify what other apps a user has installed |
7.5 | HIGH |
Yes | No | No | No | No | No | No | No | No | No |
| CVE-2026-86895 |
CloudKit |
A local app may be able to read a persistent account identifier |
7.5 | HIGH |
Yes | No | No | No | No | Yes | Yes | Yes | No | No |
| CVE-2026-84563 |
CUPS |
An app may be able to cause unexpected system termination |
7.5 | HIGH |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84606 |
iCloud |
An app may be able to identify a user across reinstalls |
7.5 | HIGH |
Yes | No | Yes | No | No | No | No | Yes | No | No |
| CVE-2026-43661 |
ImageIO |
Processing a maliciously crafted image may corrupt process memory |
7.5 | HIGH |
No | Yes | No | No | No | No | No | No | No | No |
| CVE-2026-28969 |
IOKit |
An app may be able to cause unexpected system termination |
7.5 | HIGH |
Yes | No | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-65343 |
Kernel |
A remote attacker may be able to cause unexpected system termination |
7.5 | HIGH |
No | No | No | No | No | Yes | Yes | Yes | No | No |
| CVE-2026-65364 |
Kernel |
A remote attacker may be able to cause unexpected system termination |
7.5 | HIGH |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-86894 |
libxpc |
An app may be able to break out of its sandbox |
7.5 | HIGH |
No | No | Yes | No | No | No | No | No | No | No |
| CVE-2026-84543 |
SMB |
Connecting to a malicious SMB server may cause unexpected system termination or corrupt kernel memory |
7.5 | HIGH |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84553 |
smbx |
A remote attacker may be able to cause a denial-of-service |
7.5 | HIGH |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-28930 |
Spotlight |
An app may be able to access protected user data |
7.5 | HIGH |
No | No | No | No | Yes | No | No | No | No | No |
| CVE-2026-86904 |
Watch App |
An app may be able to track users across apps and websites without permission |
7.5 | HIGH |
Yes | Yes | No | No | No | No | Yes | No | No | No |
| CVE-2026-64752 |
CoreMedia |
Processing a maliciously crafted image may lead to arbitrary code execution |
7.3 | HIGH |
Yes | No | Yes | No | No | No | No | Yes | No | No |
| CVE-2026-84611 |
SceneKit |
Processing a maliciously crafted 3D model may lead to memory corruption |
7.3 | HIGH |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-84632 |
SceneKit |
Processing a maliciously crafted 3D model may lead to memory corruption |
7.3 | HIGH |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-64736 |
IOMobileFrameBuffer |
An app may be able to cause unexpected system termination or corrupt kernel memory |
7.1 | HIGH |
No | No | No | No | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-65349 |
Kernel |
An app may be able to cause unexpected system termination or read kernel memory |
6.6 | MEDIUM |
No | No | No | No | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-84537 |
SMB |
An app may be able to cause unexpected system termination or corrupt kernel memory |
6.6 | MEDIUM |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-43788 |
Spotlight |
Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents |
6.6 | MEDIUM |
No | No | Yes | No | No | No | No | No | No | No |
| CVE-2026-86882 |
Accelerate Framework |
Processing a maliciously crafted image may lead to unexpected process termination |
6.5 | MEDIUM |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-84519 |
AppleDouble |
Mounting a disk image with maliciously crafted files may lead to unexpected system termination |
6.5 | MEDIUM |
Yes | Yes | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-86879 |
Baseband |
A remote attacker may be able to cause a denial-of-service |
6.5 | MEDIUM |
Yes | No | No | No | No | No | No | No | No | No |
| CVE-2026-86885 |
Baseband |
An attacker in radio range may be able to cause unexpected system termination |
6.5 | MEDIUM |
Yes | No | No | No | No | No | No | No | No | No |
| CVE-2026-65412 |
CoreText |
Processing web content may lead to a denial-of-service |
6.5 | MEDIUM |
Yes | Yes | Yes | Yes | Yes | No | Yes | Yes | No | No |
| CVE-2026-84596 |
CoreText |
Processing a maliciously crafted font may result in the disclosure of process memory |
6.5 | MEDIUM |
Yes | No | Yes | No | No | Yes | Yes | Yes | No | No |
| CVE-2026-84597 |
FontParser |
Processing a maliciously crafted font may result in the disclosure of process memory |
6.5 | MEDIUM |
Yes | No | Yes | No | No | Yes | Yes | Yes | No | No |
| CVE-2022-3437 |
Heimdal |
A user in a privileged network position may be able to leak sensitive user information |
6.5 | MEDIUM |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-28934 |
HFS |
Mounting a malicious disk image may cause unexpected system termination |
6.5 | MEDIUM |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-65347 |
ImageIO |
Processing an image may lead to a denial-of-service |
6.5 | MEDIUM |
No | No | No | No | No | Yes | Yes | Yes | No | No |
| CVE-2026-65395 |
ImageIO |
Processing a maliciously crafted image may result in memory corruption |
6.5 | MEDIUM |
Yes | Yes | Yes | Yes | Yes | Yes | No | Yes | No | No |
| CVE-2026-43687 |
Kernel |
Connecting to a malicious NFS server may disclose kernel memory |
6.5 | MEDIUM |
Yes | Yes | Yes | Yes | No | Yes | Yes | Yes | No | No |
| CVE-2026-65330 |
Kernel |
An app may be able to cause unexpected system termination or corrupt kernel memory |
6.5 | MEDIUM |
No | No | No | No | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-84538 |
Kernel |
A remote attacker may be able to cause a denial-of-service |
6.5 | MEDIUM |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84588 |
Kernel |
Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory |
6.5 | MEDIUM |
No | No | Yes | No | No | No | No | No | No | No |
| CVE-2026-84487 |
SceneKit |
Processing a maliciously crafted file may result in disclosure of process memory |
6.5 | MEDIUM |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-43719 |
SMB |
Mounting a maliciously crafted SMB network share may lead to system termination |
6.5 | MEDIUM |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-65365 |
SMB |
Connecting to a malicious SMB share may disclose kernel memory |
6.5 | MEDIUM |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84536 |
SMB |
Connecting to a malicious SMB server may lead to unexpected system termination |
6.5 | MEDIUM |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-43677 |
WebDAV |
Connecting to a malicious WebDAV server may lead to unexpected app termination |
6.5 | MEDIUM |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-64715 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected process crash |
6.5 | MEDIUM |
No | No | No | No | No | Yes | Yes | Yes | No | No |
| CVE-2026-64753 |
WebKit |
Processing maliciously crafted web content may disclose sensitive user information |
6.5 | MEDIUM |
Yes | No | Yes | No | No | Yes | Yes | Yes | Yes | No |
| CVE-2026-64787 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected process termination |
6.5 | MEDIUM |
No | No | No | No | No | Yes | Yes | Yes | No | No |
| CVE-2026-64778 |
WebKit History |
Visiting a maliciously crafted website may leak sensitive data |
6.5 | MEDIUM |
No | No | No | No | No | Yes | Yes | Yes | No | No |
| CVE-2026-84560 |
Bluetooth |
An app may gain unauthorized access to Bluetooth |
6.1 | MEDIUM |
Yes | No | Yes | No | No | Yes | Yes | Yes | No | No |
| CVE-2026-84619 |
Kernel |
An app may be able to cause unexpected system termination or write kernel memory |
6.1 | MEDIUM |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84554 |
CUPS |
An attacker in a privileged network position may be able to cause a denial-of-service |
5.9 | MEDIUM |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-43664 |
Accessibility |
An app may be able to access sensitive user data |
5.5 | MEDIUM |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No | No |
| CVE-2026-65404 |
Accounts |
A malicious application may be able to bypass Privacy preferences |
5.5 | MEDIUM |
Yes | No | Yes | No | No | No | No | No | No | No |
| CVE-2026-84523 |
APFS |
An app may be able to cause unexpected system termination or write kernel memory |
5.5 | MEDIUM |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-84586 |
Apple Account |
A malicious application may be able to leak sensitive user information |
5.5 | MEDIUM |
No | No | Yes | No | No | No | Yes | No | No | No |
| CVE-2026-65407 |
AppleAVD |
An app may be able to cause unexpected system termination |
5.5 | MEDIUM |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-84593 |
AppleKeyStore |
An app may be able to cause unexpected system termination |
5.5 | MEDIUM |
Yes | No | No | No | No | No | No | No | No | No |
| CVE-2026-43763 |
ATS |
An app may be able to read files outside of its sandbox |
5.5 | MEDIUM |
No | No | No | Yes | Yes | No | No | No | No | No |
| CVE-2026-86905 |
Authentication Services |
An app may be able to delete credentials stored in Keychain |
5.5 | MEDIUM |
Yes | No | Yes | No | No | No | No | Yes | No | No |
| CVE-2026-43737 |
CoreMotion |
An app may be able to access motion data from headphones without user consent |
5.5 | MEDIUM |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No | No |
| CVE-2026-43738 |
CoreUI |
Processing a maliciously crafted asset catalog may result in disclosure of process memory |
5.5 | MEDIUM |
Yes | No | Yes | No | No | No | No | No | No | No |
| CVE-2026-84489 |
CoreUI |
An app may be able to cause a denial of service |
5.5 | MEDIUM |
Yes | No | Yes | No | No | No | No | No | No | No |
| CVE-2026-84534 |
file_cmds |
Extracting a maliciously crafted archive may allow an attacker to write arbitrary files |
5.5 | MEDIUM |
Yes | Yes | Yes | Yes | Yes | No | No | Yes | No | No |
| CVE-2026-65409 |
Foundation |
An app may be able to cause a denial of service |
5.5 | MEDIUM |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-64756 |
Image Capture |
An app may be able to access user-sensitive data |
5.5 | MEDIUM |
Yes | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-64760 |
IOSurfaceAccelerator |
An app may be able to leak sensitive kernel state |
5.5 | MEDIUM |
Yes | No | Yes | No | No | Yes | Yes | Yes | No | No |
| CVE-2026-65401 |
Kernel |
An app may be able to cause unexpected system termination |
5.5 | MEDIUM |
No | No | Yes | Yes | No | No | No | No | No | No |
| CVE-2026-65402 |
Kernel |
An app may be able to cause unexpected system termination |
5.5 | MEDIUM |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-65405 |
Kernel |
An app may be able to determine kernel memory layout |
5.5 | MEDIUM |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-84517 |
Kernel |
An app may be able to cause unexpected system termination |
5.5 | MEDIUM |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84521 |
Kernel |
An app may be able to cause unexpected system termination |
5.5 | MEDIUM |
Yes | Yes | Yes | Yes | Yes | No | No | Yes | No | No |
| CVE-2026-86903 |
Kernel |
An app may be able to disclose kernel memory |
5.5 | MEDIUM |
Yes | No | Yes | No | No | Yes | Yes | Yes | No | No |
| CVE-2026-86883 |
Managed Configuration |
An app may be able to access sensitive user data |
5.5 | MEDIUM |
Yes | No | No | No | No | No | No | Yes | No | No |
| CVE-2026-43741 |
Messages |
An app may be able to access protected user data |
5.5 | MEDIUM |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84491 |
Photos Storage |
An app may be able to access sensitive user data |
5.5 | MEDIUM |
Yes | Yes | Yes | No | No | Yes | Yes | Yes | No | No |
| CVE-2026-84576 |
QuartzCore |
An app may be able to access sensitive user data |
5.5 | MEDIUM |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84555 |
Sandbox |
An app may be able to access sensitive user data |
5.5 | MEDIUM |
No | No | Yes | No | Yes | No | No | No | No | No |
| CVE-2026-65413 |
SceneKit |
An app may be able to cause a denial of service |
5.5 | MEDIUM |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-28937 |
Terminal |
An app may be able to access sensitive user data |
5.5 | MEDIUM |
No | No | Yes | No | No | No | No | No | No | No |
| CVE-2026-64718 |
WebKit Canvas |
Processing maliciously crafted web content may lead to an unexpected Safari crash |
5.5 | MEDIUM |
Yes | Yes | Yes | No | No | No | No | Yes | Yes | No |
| CVE-2026-65393 |
Xcode IDE |
An app may be able to access user-sensitive data |
5.5 | MEDIUM |
No | No | Yes | No | No | No | No | No | No | Yes |
| CVE-2026-84617 |
XPC |
An app may be able to access sensitive user data |
5.5 | MEDIUM |
Yes | Yes | Yes | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-64788 |
IOGPUFamily |
Processing maliciously crafted web content may lead to memory corruption |
5.4 | MEDIUM |
No | No | No | No | No | No | Yes | Yes | No | No |
| CVE-2026-65341 |
WebKit |
Processing maliciously crafted web content may lead to memory corruption |
5.4 | MEDIUM |
No | No | No | No | No | Yes | Yes | Yes | No | No |
| CVE-2026-34979 |
CUPS |
An attacker in a privileged network position may be able to cause a denial-of-service |
5.3 | MEDIUM |
No | No | Yes | No | No | No | No | No | No | No |
| CVE-2026-86876 |
CoreMedia |
A sandboxed process may be able to circumvent sandbox restrictions |
5.2 | MEDIUM |
Yes | Yes | Yes | Yes | Yes | No | Yes | Yes | No | No |
| CVE-2026-86889 |
Security |
An attacker in a privileged network position may be able to intercept network traffic |
4.8 | MEDIUM |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84492 |
Graphics |
An app may be able to cause unexpected system termination |
4.7 | MEDIUM |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-84630 |
Kernel |
An app may be able to cause unexpected system termination |
4.7 | MEDIUM |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-43690 |
SMB |
A local user may be able to read kernel memory |
4.7 | MEDIUM |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84518 |
Safari |
A malicious website may be able to determine what apps a user has installed |
4.3 | MEDIUM |
Yes | No | Yes | No | No | No | No | No | Yes | No |
| CVE-2026-43795 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected Safari crash |
4.3 | MEDIUM |
No | No | No | No | No | No | No | Yes | No | No |
| CVE-2026-64780 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected Safari crash |
4.3 | MEDIUM |
No | No | No | No | No | No | No | Yes | No | No |
| CVE-2026-64781 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected Safari crash |
4.3 | MEDIUM |
No | No | No | No | No | No | No | Yes | No | No |
| CVE-2026-64784 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected Safari crash |
4.3 | MEDIUM |
No | No | No | No | No | No | No | Yes | No | No |
| CVE-2026-65331 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected Safari crash |
4.3 | MEDIUM |
No | No | No | No | No | No | No | Yes | No | No |
| CVE-2026-65332 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected Safari crash |
4.3 | MEDIUM |
No | No | No | No | No | No | No | Yes | No | No |
| CVE-2026-65333 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected Safari crash |
4.3 | MEDIUM |
No | No | No | No | No | No | No | Yes | No | No |
| CVE-2026-65334 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected Safari crash |
4.3 | MEDIUM |
No | No | No | No | No | No | No | Yes | No | No |
| CVE-2026-65335 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected Safari crash |
4.3 | MEDIUM |
No | No | No | No | No | No | No | Yes | No | No |
| CVE-2026-65336 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected Safari crash |
4.3 | MEDIUM |
No | No | No | No | No | No | No | Yes | No | No |
| CVE-2026-65337 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected Safari crash |
4.3 | MEDIUM |
No | No | No | No | No | No | No | Yes | No | No |
| CVE-2026-65338 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected Safari crash |
4.3 | MEDIUM |
No | No | No | No | No | No | No | Yes | No | No |
| CVE-2026-65340 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected Safari crash |
4.3 | MEDIUM |
No | No | No | No | No | No | No | Yes | No | No |
| CVE-2026-65351 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected Safari crash |
4.3 | MEDIUM |
No | No | No | No | No | No | No | Yes | No | No |
| CVE-2026-64782 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected Safari crash |
3.1 | LOW |
No | No | No | No | No | No | No | Yes | No | No |
| CVE-2026-64779 |
WebKit Storage |
Processing maliciously crafted web content may lead to an unexpected Safari crash |
3.1 | LOW |
No | No | No | No | No | No | No | Yes | No | No |
| CVE-2026-86910 |
APFS |
An application may be able to access restricted files |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-86888 |
App Store |
A local app may be able to read a persistent account identifier |
TBD | TBD |
Yes | No | Yes | Yes | No | Yes | Yes | Yes | No | No |
| CVE-2026-84587 |
AppKit |
An app may be able to access protected user data |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-20683 |
Apple Account |
An app may be able to use the Sign In With Apple authentication flow to access the user's Apple Account |
TBD | TBD |
Yes | No | Yes | Yes | Yes | No | No | Yes | No | No |
| CVE-2026-84601 |
Apple Intelligence |
An app may be able to bypass Apple Intelligence security prompts |
TBD | TBD |
No | No | Yes | No | No | No | No | No | No | No |
| CVE-2026-65408 |
Apple Neural Engine |
An app may be able to cause unexpected system termination |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84520 |
AppleFDEKeyStore |
A local attacker may be able to cause unexpected system termination or corrupt kernel memory |
TBD | TBD |
No | No | Yes | No | No | No | No | No | No | No |
| CVE-2026-65381 |
AppleMobileFileIntegrity |
A malicious app may be able to break out of its sandbox |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84522 |
Archive Utility |
An app may be able to access sensitive user data |
TBD | TBD |
No | No | Yes | No | No | No | No | No | No | No |
| CVE-2026-84584 |
Archive Utility |
An app may be able to break out of its sandbox |
TBD | TBD |
No | No | Yes | No | No | No | No | No | No | No |
| CVE-2026-65342 |
ATS |
An app may be able to access sensitive user data |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84525 |
ATS |
An app may be able to access user-sensitive data |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-65339 |
Audio |
An app may be able to leak sensitive user information |
TBD | TBD |
No | No | No | No | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-84583 |
AuthKit |
A local app may be able to read a persistent account identifier |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-84570 |
autofs |
An app may be able to bypass Gatekeeper checks |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-65410 |
AVEVideoEncoder |
An app may be able to cause unexpected system termination |
TBD | TBD |
Yes | Yes | Yes | Yes | No | Yes | Yes | Yes | No | No |
| CVE-2026-84616 |
AVEVideoEncoder |
An app may be able to cause unexpected system termination |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-65406 |
BackgroundAssets |
An app may be able to access sensitive user data |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | Yes | No | Yes | No | No |
| CVE-2026-86878 |
Camera |
An app may be able to access sensitive user data |
TBD | TBD |
Yes | No | No | No | No | No | No | No | No | No |
| CVE-2026-84567 |
cd9660 |
An app may be able to cause unexpected system termination |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-86893 |
CloudKit |
An app may be able to read device name |
TBD | TBD |
Yes | No | No | No | No | Yes | Yes | Yes | No | No |
| CVE-2026-65399 |
copyfile |
An archive may be able to bypass Gatekeeper |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | No | Yes | Yes | No | No |
| CVE-2026-86891 |
Core Bluetooth |
An app may be able to access Bluetooth device information |
TBD | TBD |
No | No | Yes | Yes | Yes | No | Yes | No | No | No |
| CVE-2026-43683 |
CoreDrag |
An app may be able to cause unexpected process termination or disclose process memory |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-43789 |
CoreMedia |
An app may be able to access user-sensitive data |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-65344 |
CoreMedia |
Processing a maliciously crafted video file may lead to unexpected app termination |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | Yes | No | Yes | No | No |
| CVE-2026-43702 |
CoreMedia Video Toolbox |
Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory |
TBD | TBD |
No | Yes | No | Yes | Yes | No | No | No | No | No |
| CVE-2026-84624 |
CoreML |
A sandboxed app may be able to access restricted files |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | No | No | Yes | No | No |
| CVE-2026-84559 |
CoreServices |
A malicious application may be able to access restricted files |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84574 |
CoreServices |
An app may be able to bypass Privacy preferences |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84511 |
CoreUI |
Processing a maliciously crafted asset catalog may lead to unexpected process termination |
TBD | TBD |
Yes | No | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-84571 |
CoreUI |
Processing a maliciously crafted image may lead to unexpected app termination |
TBD | TBD |
Yes | No | Yes | No | No | Yes | Yes | Yes | No | No |
| CVE-2026-64790 |
CUPS |
An app may be able to gain elevated privileges |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84540 |
CUPS |
An app may be able to access sensitive user data |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84541 |
CUPS |
An application may be able to access restricted files |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84612 |
DeviceCheck |
An app may be able to read persistent device identifiers |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-84512 |
Disk Images |
Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84550 |
Disk Images |
An app may be able to cause unexpected system termination |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84552 |
Disk Images |
An app may be able to cause unexpected system termination |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84565 |
Disk Images |
Processing a maliciously crafted disk image may lead to unexpected app termination |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84510 |
exFAT |
Mounting a maliciously crafted volume may lead to unexpected system termination |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-86900 |
exFAT |
Mounting a maliciously crafted exFAT volume may cause unexpected system termination or kernel memory disclosure |
TBD | TBD |
No | No | Yes | No | No | No | No | No | No | No |
| CVE-2026-86901 |
exFAT |
Mounting a maliciously crafted exFAT volume may cause unexpected system termination or kernel memory disclosure |
TBD | TBD |
No | No | Yes | No | No | No | No | No | No | No |
| CVE-2026-43785 |
File Bookmark |
An app may be able to modify a file it only had permission to read |
TBD | TBD |
Yes | No | Yes | Yes | Yes | Yes | No | Yes | No | No |
| CVE-2026-43688 |
Filters |
Processing a maliciously crafted file may lead to unexpected app termination |
TBD | TBD |
Yes | No | Yes | No | No | No | No | No | No | No |
| CVE-2026-84524 |
FontParser |
Processing a maliciously crafted font file may lead to unexpected app termination |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-84569 |
Foundation |
An app may be able to access sensitive user data |
TBD | TBD |
No | No | Yes | No | No | No | No | No | No | No |
| CVE-2026-86911 |
Foundation |
A malicious app may be able to bypass clickjacking protections for secure prompts |
TBD | TBD |
No | No | Yes | No | No | No | No | No | No | No |
| CVE-2026-84618 |
Game Center |
An app may be able to access sensitive user data |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84533 |
Heimdal |
An attacker in a privileged network position may be able to modify network traffic |
TBD | TBD |
Yes | No | Yes | No | No | Yes | Yes | No | No | No |
| CVE-2026-64714 |
ImageIO |
Processing a maliciously crafted image may lead to a denial-of-service |
TBD | TBD |
No | No | Yes | No | No | No | No | No | No | No |
| CVE-2026-84564 |
ImageIO |
Processing a maliciously crafted image may result in disclosure of process memory |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-86869 |
ImageIO |
Processing a maliciously crafted image may lead to unexpected app termination |
TBD | TBD |
No | Yes | Yes | No | No | No | No | No | No | No |
| CVE-2026-43743 |
IOGPUFamily |
An app may be able to cause unexpected system termination |
TBD | TBD |
No | Yes | No | Yes | No | No | No | No | No | No |
| CVE-2026-65398 |
IOMobileFrameBuffer |
An app may be able to cause unexpected system termination or corrupt kernel memory |
TBD | TBD |
Yes | No | Yes | No | No | Yes | Yes | Yes | No | No |
| CVE-2026-65354 |
iWork |
A malicious app may be able to break out of its sandbox |
TBD | TBD |
Yes | No | Yes | No | No | No | No | No | No | No |
| CVE-2026-28935 |
Kernel |
An app may be able to cause unexpected system termination or corrupt kernel memory |
TBD | TBD |
No | No | No | No | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-28968 |
Kernel |
An app may be able to cause unexpected system termination or corrupt kernel memory |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-43790 |
Kernel |
A remote attacker may be able to cause unexpected system termination or corrupt kernel memory |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-65358 |
Kernel |
An app may be able to cause unexpected system termination |
TBD | TBD |
Yes | No | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-65359 |
Kernel |
A local user may be able to cause unexpected system termination or read kernel memory |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-65360 |
Kernel |
An app may be able to cause unexpected system termination |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-65369 |
Kernel |
A malicious application may bypass Gatekeeper checks |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-65371 |
Kernel |
An app may be able to disclose kernel memory |
TBD | TBD |
No | No | No | No | Yes | No | No | No | No | No |
| CVE-2026-65377 |
Kernel |
An app may be able to cause unexpected system termination |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-84507 |
Kernel |
An app may be able to cause unexpected system termination or corrupt kernel memory |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-84530 |
Kernel |
An app may be able to disclose kernel memory |
TBD | TBD |
Yes | Yes | Yes | Yes | No | Yes | Yes | Yes | No | No |
| CVE-2026-84544 |
Kernel |
Connecting to a malicious NFS server may cause unexpected system termination or corrupt kernel memory |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84549 |
Kernel |
Connecting to a malicious NFS server may cause unexpected system termination or corrupt kernel memory |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84558 |
Kernel |
An app may be able to cause unexpected system termination |
TBD | TBD |
No | No | Yes | No | No | No | No | No | No | No |
| CVE-2026-84561 |
Kernel |
An app may be able to cause unexpected system termination or corrupt kernel memory |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-84566 |
Kernel |
A local attacker may be able to cause unexpected system termination or corrupt kernel memory |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84602 |
Kernel |
An app may be able to cause unexpected system termination |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-84622 |
Kernel |
An app with root privileges may be able to read uninitialized kernel memory |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-84514 |
Kext Management |
An app may be able to modify protected parts of the file system |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84556 |
Keychain Access |
An app may be able to access sensitive user data |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-65382 |
LaunchServices |
An app may be able to access sensitive user data |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-86870 |
libarchive |
Processing a maliciously crafted file may lead to unexpected app termination |
TBD | TBD |
Yes | Yes | Yes | No | No | No | Yes | Yes | No | No |
| CVE-2026-84577 |
libxpc |
An app may be able to bypass sandbox restrictions |
TBD | TBD |
No | No | Yes | Yes | No | No | No | No | No | No |
| CVE-2026-43787 |
Mail |
An attacker in a privileged network position may be able to leak sensitive user information |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84573 |
Mail |
An app may be able to access sensitive user data |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84628 |
MediaRemote |
A sandboxed app may be able to access the System Keychain |
TBD | TBD |
Yes | No | Yes | No | No | Yes | Yes | Yes | No | No |
| CVE-2026-86924 |
MobileAccessoryUpdater |
Connecting a malicious accessory may cause unexpected system termination |
TBD | TBD |
Yes | Yes | Yes | Yes | No | No | No | No | No | No |
| CVE-2026-65411 |
MobileBackup |
An app may be able to modify protected parts of the file system |
TBD | TBD |
Yes | Yes | No | No | No | No | No | Yes | No | No |
| CVE-2026-84598 |
MobileBackup |
An attacker with physical access to a trust-paired device may be able to read and write arbitrary files |
TBD | TBD |
Yes | Yes | No | No | No | No | No | No | No | No |
| CVE-2026-84497 |
Model I/O |
Opening a maliciously crafted file may lead to unexpected process termination |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | Yes | No | Yes | No | No |
| CVE-2026-84615 |
Music |
An app may be able to access sensitive user data |
TBD | TBD |
Yes | Yes | No | No | No | Yes | No | Yes | No | No |
| CVE-2026-43695 |
NetworkExtension |
An app may be able to access sensitive user data |
TBD | TBD |
Yes | No | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-84585 |
NetworkExtension |
An app may be able to access local network devices without user consent |
TBD | TBD |
No | No | Yes | No | No | No | No | No | No | No |
| CVE-2026-84626 |
NetworkExtension |
An app may be able to identify what other apps a user has installed |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-86902 |
NSDocument |
An app may be able to access sensitive user data |
TBD | TBD |
No | No | Yes | No | No | No | No | No | No | No |
| CVE-2026-84629 |
Photos Storage |
An app may be able to fingerprint the user |
TBD | TBD |
Yes | No | No | No | No | Yes | Yes | Yes | No | No |
| CVE-2026-84623 |
Power Management |
An app may be able to fingerprint the device |
TBD | TBD |
Yes | Yes | No | No | No | No | No | No | No | No |
| CVE-2026-84578 |
quarantine |
An app may be able to break out of its sandbox |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84580 |
quarantine |
An app may be able to break out of its sandbox |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84548 |
Quick Look |
Processing a maliciously crafted document may lead to an out-of-bounds read |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-28966 |
RealityKit |
Processing a maliciously crafted file may lead to unexpected app termination |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | Yes | No | Yes | No | No |
| CVE-2026-84532 |
RealityKit |
Opening a maliciously crafted file may cause unexpected process termination or disclose process memory |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | Yes | No | Yes | No | No |
| CVE-2026-65403 |
Reminders |
An app may be able to access sensitive user data |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | No | Yes | Yes | No | No |
| CVE-2026-86897 |
Safe Browsing |
An app may be able to access sensitive user data |
TBD | TBD |
Yes | Yes | Yes | No | No | No | No | Yes | Yes | No |
| CVE-2026-65380 |
Sandbox |
An app may be able to access protected user data |
TBD | TBD |
No | No | Yes | No | No | No | No | No | No | No |
| CVE-2026-84551 |
Sandbox |
An app may be able to bypass network restrictions |
TBD | TBD |
Yes | No | Yes | No | No | No | Yes | Yes | No | No |
| CVE-2026-84603 |
Sandbox Profiles |
An app may be able to access sensitive user data |
TBD | TBD |
Yes | No | No | No | No | No | Yes | Yes | No | No |
| CVE-2026-84625 |
Sandbox Profiles |
An app may be able to fingerprint the user |
TBD | TBD |
Yes | No | Yes | No | No | No | Yes | Yes | No | No |
| CVE-2026-43697 |
SceneKit |
Processing a maliciously crafted 3D file may lead to an out-of-bounds read |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84526 |
SceneKit |
Processing a maliciously crafted 3D scene may lead to unexpected process termination |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-84546 |
SceneKit |
Processing a maliciously crafted 3D model may lead to memory corruption |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-84620 |
SceneKit |
Processing a maliciously crafted 3D model may lead to memory corruption |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-84531 |
Security |
Processing maliciously crafted NTLM input may lead to unexpected app termination |
TBD | TBD |
Yes | No | Yes | No | No | No | No | No | No | No |
| CVE-2026-86881 |
Security |
An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-84600 |
Shortcuts |
A malicious shortcut may be able to send messages without user confirmation |
TBD | TBD |
Yes | No | Yes | No | No | Yes | Yes | Yes | No | No |
| CVE-2026-86884 |
Siri |
An app may be able to access sensitive user data |
TBD | TBD |
Yes | No | Yes | No | No | Yes | Yes | No | No | No |
| CVE-2026-86890 |
Siri Suggestions |
An attacker with physical access to a locked device may be able to view sensitive user information |
TBD | TBD |
Yes | Yes | No | No | No | No | No | No | No | No |
| CVE-2026-65376 |
SMB |
An app may be able to cause unexpected system termination |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84509 |
SMB |
Connecting to a malicious SMB server may lead to unexpected system termination |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84609 |
Software Update |
An app may be able to modify protected system files |
TBD | TBD |
Yes | No | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-65361 |
SoftwareUpdate |
An app may be able to access sensitive user data |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-65378 |
Spotlight |
An app may be able to access sensitive user data |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84621 |
Spotlight |
An app may be able to access sensitive user data |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-86892 |
SpringBoard |
An app may be able to cause a denial-of-service |
TBD | TBD |
Yes | Yes | No | No | No | No | No | Yes | No | No |
| CVE-2026-65345 |
Storage |
An app may be able to access user-sensitive data |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-65348 |
Storage |
An app may be able to modify protected parts of the file system |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-43791 |
StorageKit |
An app may be able to read arbitrary files |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-84513 |
Symptom Framework |
A malicious application may be able to determine a user's current location |
TBD | TBD |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-65383 |
System Settings |
An app may bypass Gatekeeper checks |
TBD | TBD |
No | No | Yes | No | No | No | No | No | No | No |
| CVE-2026-86909 |
System Settings |
An app may be able to bypass Gatekeeper checks |
TBD | TBD |
No | No | Yes | No | No | No | No | No | No | No |
| CVE-2026-84527 |
TCC |
An app may be able to access sensitive user data |
TBD | TBD |
Yes | No | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-84589 |
TCC |
An app may be able to modify Privacy preferences |
TBD | TBD |
No | No | Yes | No | No | No | No | No | No | No |
| CVE-2026-86886 |
TCC |
An app may be able to modify protected system files |
TBD | TBD |
Yes | Yes | No | No | No | No | Yes | No | No | No |
| CVE-2026-65329 |
Telephony |
An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic |
TBD | TBD |
Yes | No | No | No | No | No | No | No | No | No |
| CVE-2026-86887 |
Time Zone |
An app may be able to bypass certain Privacy preferences |
TBD | TBD |
Yes | Yes | No | No | No | No | No | Yes | No | No |
| CVE-2026-43696 |
Touch Bar |
An app may be able to capture Touch Bar content without authorization |
TBD | TBD |
No | No | Yes | No | No | No | No | No | No | No |
| CVE-2026-84572 |
udf |
An app may be able to cause unexpected system termination or read kernel memory |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-28899 |
WebDAV |
An app may bypass Gatekeeper checks |
TBD | TBD |
No | No | Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-65375 |
WebDAV |
An app may be able to cause unexpected system termination |
TBD | TBD |
No | No | Yes | No | Yes | No | No | No | No | No |
| CVE-2026-84635 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected process termination |
TBD | TBD |
Yes | No | Yes | No | No | Yes | Yes | Yes | Yes | No |
| CVE-2026-86898 |
WebKit |
Opening a maliciously crafted webarchive file may lead to universal cross-site scripting |
TBD | TBD |
Yes | No | Yes | No | No | No | No | Yes | Yes | No |
| CVE-2026-84636 |
Wi-Fi Connectivity |
An app may be able to access sensitive user data |
TBD | TBD |
Yes | No | No | No | No | Yes | Yes | Yes | No | No |
| CVE-2026-43674 |
Wi-Fi3 |
An attacker with physical access to an unlocked device may be able to view Wi-Fi passwords without authentication |
TBD | TBD |
Yes | No | No | No | No | No | No | No | No | No |