ZeroHour
Zero Day Initiative Blogpublished ()ingested Dustin Childs

The Apple Security Update Review for September 2026

AI summary · glm-5.3-flash

Apple's September 2026 updates patch 45+ flaws, including a 9.8 Screen Sharing authentication bypass (CVE-2026-65400) already listed in CISA's KEV.

ZDI's review of Apple's September 2026 security updates catalogs dozens of CVEs across macOS, iOS, iPadOS, watchOS and other platforms. CVE-2026-65400 (CVSS 9.8) lets a network attacker authenticate to Screen Sharing Server without valid credentials and is flagged as KEV, while CVE-2026-65414 (CVSS 9.8) enables remote code execution via Bluetooth. The set also includes 8.8-rated memory corruption flaws in WebKit, WebRTC, CUPS, ImageIO and the kernel, plus sandbox escapes, privilege escalations to root, and arbitrary code execution via crafted files.

  • CVE-2026-65400 (CVSS 9.8) allows network authentication to Screen Sharing without credentials; flagged KEV.
  • CVE-2026-65414 (CVSS 9.8) enables unexpected app termination or arbitrary code execution via Bluetooth.
  • WebKit and WebRTC memory corruption flaws (CVSS 8.8) allow code execution via crafted web content.
  • Malicious NFS, SMB, and WebDAV servers can trigger kernel memory corruption or code execution.
  • Multiple sandbox escapes and root privilege escalation bugs affect core system components.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-65414
Out-of-Bounds Write in Apple iOS, iPadOS, macOS Enables Remote Code Execution

Apple patched a critical out-of-bounds write (CWE-787) memory-corruption flaw spanning nearly its entire operating-system lineup: iOS, iPadOS, macOS (Sequoia, Tahoe, Golden Gate), tvOS, visionOS, and watchOS. A remote attacker could trigger the flaw with no privileges and no user interaction (CVSS 3.1: 9.8, network vector, low complexity), causing unexpected app termination or potentially arbitrary code execution on the affected device. The advisory does not identify the vulnerable component or exact trigger, so defenders should assume any affected system is remotely attackable until patched. All users running iOS/iPadOS before 26.7, macOS Sequoia before 15.8, macOS Tahoe before 26.7, or pre-release tvOS/visionOS/watchOS builds older than 27 are affected. No public proof of concept exists, no exploitation in the wild is known, and the flaw is not on CISA's KEV list; fixes shipped in the listed updates.

Do: Update all Apple devices promptly: iPhones/iPads to iOS/iPadOS 26.7 or 27, Macs to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27, Apple TV to tvOS 27, Apple Watch to watchOS 27, and Vision Pro to visionOS 27. Enable automatic security updates and use MDM/inventory to find devices still on older OS trains. Given the 9.8 CVSS with no user interaction required, treat patching as high priority even though no exploitation has been observed.

9.8
group max
  • Apple iOS Prior to iOS 26.7 (26.x and earlier trains); fixed in iOS 26.7 and iOS 27
  • Apple iPadOS Prior to iPadOS 26.7 (26.x and earlier trains); fixed in iPadOS 26.7 and iPadOS 27
  • Apple macOS Sequoia Prior to 15.8; fixed in 15.8
  • +5 more
masspotentially 1+ billion devices (Apple's ~2.35 billion active-device install base, most on affected OS trains)
CVE-2026-65374
Memory Corruption RCE via Malicious WebDAV Server in Apple macOS

CVE-2026-65374 is an out-of-bounds write (memory corruption) flaw in Apple macOS's handling of WebDAV connections, rated 8.8 (high) with network vector, low attack complexity, no privileges required, but user interaction required. It is triggered when a victim connects to an attacker-controlled WebDAV server — for example by clicking a webdav:// link or mounting an untrusted WebDAV share via Finder's 'Connect to Server' — and the malformed server responses corrupt memory in the WebDAV client code. Successful exploitation can yield arbitrary code execution with the privileges of the connecting user, impacting confidentiality, integrity, and availability. All Macs running macOS Sequoia before 15.8, macOS Tahoe before 26.7, and macOS Golden Gate before 27 are affected; Apple addressed the issue with improved validation. No public proof-of-concept is known and the flaw is not on the CISA KEV catalog, so there is no evidence of in-the-wild exploitation at this time.

Do: Patch to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27 (System Settings > Software Update), prioritizing fleets where users mount network shares. Advise users not to click webdav:// links or connect to WebDAV servers from untrusted sources, since the flaw requires user interaction. Egress/URL filtering can also block or flag webdav:// schemes and unexpected outbound WebDAV (TCP 80/443 with WebDAV methods) as a defense-in-depth measure.

8.8
group max
<1% PoC
  • Apple macOS Sequoia versions prior to 15.8
  • Apple macOS Tahoe versions prior to 26.7
  • Apple macOS Golden Gate versions prior to 27
masstens of millions of Macs (est. >1M, likely 10M–100M+ devices on unpatched macOS versions)
CVE-2026-43760
+1 in the same advisory: …43698
An access issue was addressed with improved access restrictions.

An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6, macOS Tahoe 26.7. An app may be able to access user-sensitive data.

NVD description · AI analysis pending
8.6
group max
<1%
  • apple macos
CVE-2026-43715
A use-after-free issue was addressed with improved memory management.

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, iOS 26.7 and iPadOS 26.7, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.

NVD description · AI analysis pending
8.8<1%
  • apple safari
  • apple ipados
  • apple iphone os
  • +1 more
CVE-2026-43794
Memory Corruption in Apple Safari and OS Web Content Handling Across iOS, iPadOS, macOS

CVE-2026-43794 is a memory corruption flaw (CWE-119) in Apple's handling of web content, addressed with improved memory handling in the September 2026 Apple security updates. It is triggered when a user processes maliciously crafted web content — for example, by loading an attacker-controlled page — which the CVSS vector confirms requires user interaction (UI:R) but no privileges. Successful exploitation could compromise confidentiality, integrity, and availability (all rated High), consistent with a memory corruption bug that may permit arbitrary code execution or crashes on the affected device. Anyone using Safari or the affected Apple operating systems on unpatched versions is exposed, which spans essentially the entire Apple user base. There is currently no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days, so no exploitation is known at this time.

Do: Update Safari to 26.6.1, iOS/iPadOS to 18.7.10 (older devices) or 26.6.1 (current generation), macOS Tahoe to 26.6.2, and tvOS, visionOS, and watchOS to version 27 as soon as possible. Because the attack vector is web content, prioritize patches for user-facing endpoints such as managed Macs and iPhones. Check MDM or fleet inventory for devices stuck on older, unsupported branches and consider limiting their browsing to non-WebKit-based browsers as an interim mitigation.

8.8<1%
  • Apple Safari All versions prior to Safari 26.6.1
  • Apple iPhone OS (iOS) All versions prior to iOS 18.7.10 (older branch) and prior to iOS 26.6.1 (current branch)
  • Apple iPadOS All versions prior to iPadOS 18.7.10 (older branch) and prior to iPadOS 26.6.1 (current branch)
  • +4 more
mass≈1 billion+ devices (Apple's active installed base of iPhones, iPads, Macs, Apple TVs and Safari users)
CVE-2026-64758
The issue was addressed with improved bounds checks.

The issue was addressed with improved bounds checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination.

NVD description · AI analysis pending
7.8<1%
  • apple ipados
  • apple iphone os
  • apple macos
  • +1 more
CVE-2026-65346
Integer Overflow in Apple Image Processing Allows Arbitrary Code Execution

CVE-2026-65346 is an integer overflow (CWE-190) in the image-processing code of multiple Apple operating systems, addressed through improved input validation. An attacker can trigger it by getting a user to process a maliciously crafted image, such as opening it in a message, email, or web page, since the flaw requires user interaction but no privileges or special conditions. Successful exploitation yields arbitrary code execution with high impact on confidentiality, integrity, and availability. Every Apple user running an affected version of iOS, iPadOS, macOS, tvOS, visionOS, or watchOS is potentially affected, which is essentially the entire Apple device installed base. As of now there is no known exploitation in the wild, no public proof of concept, and a low EPSS score of 0.3%, suggesting the flaw is not yet being actively weaponized.

Do: Update all Apple devices as soon as possible: iPhone and iPad to iOS/iPadOS 26.6.1, Macs on Sequoia to 15.8 and Macs on Tahoe to 26.6.2, and Apple TV, Apple Vision Pro, and Apple Watch to tvOS 27, visionOS 27, and watchOS 27 respectively. Until patching is complete, instruct users not to open images from untrusted sources, since user interaction with a crafted image is the attack vector. There is no public exploit or reported in-the-wild exploitation, so prompt patching should fully close the window.

8.8<1%
  • apple iPhone OS (iOS) versions prior to iOS 26.6.1
  • apple iPadOS versions prior to iPadOS 26.6.1
  • apple macOS Sequoia versions prior to macOS Sequoia 15.8
  • +4 more
masshundreds of millions of devices (Apple's active installed base is over a billion devices)
CVE-2026-65390
+1 in the same advisory: …65391
Integer Overflow in Apple WebKit/Safari Allows Memory Corruption from Malicious Web Content

CVE-2026-65390 is an integer overflow (CWE-190) in Apple's WebKit browser engine that was fixed with improved input validation. The flaw is triggered when a victim processes maliciously crafted web content — for example, visiting an attacker-controlled or compromised website — which can lead to memory corruption and potential arbitrary code execution within the browser context, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8; network vector, no privileges required, but user interaction required). Affected products span Apple's entire device lineup: Safari on macOS, plus iPhone, iPad, Mac (Tahoe), Apple TV, Apple Watch, and Apple Vision Pro. Notably, on iOS and iPadOS all third-party browsers (Chrome, Firefox, etc.) also use WebKit, so any browser on an unpatched Apple device is exposed. There is currently no evidence of exploitation in the wild, no public proof of concept, and the CVE is not in CISA's Known Exploited Vulnerabilities catalog.

Do: Update all Apple devices promptly: Safari 26.6.1 and macOS Tahoe 26.6.2 on Macs, iOS/iPadOS 26.6.1 on iPhones and iPads, and tvOS/visionOS/watchOS 27 on Apple TV, Vision Pro, and Apple Watch. On iOS/iPadOS, remember the OS update also patches WebKit for every third-party browser, so a Safari-only workaround is insufficient. Because exploitation requires the user to load malicious web content, block known-malicious links in mail/web filters where possible and verify patch compliance via MDM or Software Update status.

8.8
  • Apple Safari (macOS) prior to 26.6.1
  • Apple iOS prior to 26.6.1
  • Apple iPadOS prior to 26.6.1
  • +4 more
mass≈1-2 billion devices (order of magnitude), given WebKit ships on effectively all Apple hardware
CVE-2026-65400
Authentication Bypass in Apple macOS Screen Sharing

CVE-2026-65400 is a critical (CVSS 9.8) improper authentication flaw (CWE-287) in Apple macOS's Screen Sharing service, caused by an authentication state-management defect. An attacker who can reach a vulnerable Mac's Screen Sharing service over the network can authenticate without valid credentials, gaining full remote access with high impact to confidentiality, integrity, and availability. All three currently supported macOS branches are affected: Sequoia, Sonoma, and Tahoe, in versions prior to the fixed releases. The flaw is being actively exploited on the internet, with public reporting that attackers use the bypass to deploy Monero cryptominers, and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-18. EPSS estimates a 9.9% probability of exploitation within 30 days (95th percentile).

Do: Upgrade to macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, or macOS Tahoe 26.6.1 (or later) immediately; patching is mandatory for federal agencies under CISA BOD 26-04 given the KEV listing. As an interim mitigation, disable Screen Sharing or restrict it via firewall/VPN so VNC (port 5900) is not reachable from the internet. Review internet-exposed Macs for signs of compromise, especially unexplained Monero miner processes or abnormal CPU usage.

9.810% KEV
  • Apple macOS (Screen Sharing service) supported macOS releases prior to the fixed builds listed below
  • Apple macOS Sequoia all versions prior to 15.7.9
  • Apple macOS Sonoma all versions prior to 14.8.9
  • +1 more
masson the order of 100M+ Macs run affected macOS versions; the directly exploitable subset is Macs with Screen Sharing enabled and internet-reachable
Full article3,742 words · extracted from thezdi.com · click to collapse
CVE-2026-65400 Screen Sharing Server An attacker on the network may be able to authenticate to Screen Sharing without valid credentials 9.8⚠ KEV CRITICAL NoNoYesYesNoNoNoNoNoNo CVE-2026-65414 Bluetooth A remote attacker may be able to cause unexpected app termination or arbitrary code execution 9.8CRITICAL YesYesYesYesYesYesYesYesNoNo CVE-2026-43692 CUPS A remote user may cause an unexpected app termination or arbitrary code execution 8.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-65346 ImageIO Processing an image may lead to arbitrary code execution 8.8HIGH NoNoNoNoYesYesYesYesNoNo CVE-2026-43686 Kernel Connecting to a malicious NFS server may lead to kernel memory corruption 8.8HIGH YesYesYesYesYesYesYesYesNoNo CVE-2026-65374 WebDAV Connecting to a malicious WebDAV server may result in code execution 8.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-43715 WebKit Processing maliciously crafted web content may lead to memory corruption 8.8HIGH NoYesNoNoNoNoNoNoNoNo CVE-2026-43794 WebKit Processing maliciously crafted web content may lead to memory corruption 8.8HIGH NoNoNoNoNoYesYesYesNoNo CVE-2026-65390 WebRTC Processing maliciously crafted web content may lead to memory corruption 8.8HIGH NoNoNoNoNoYesYesYesNoNo CVE-2026-65391 WebRTC Processing maliciously crafted web content may lead to memory corruption 8.8HIGH NoNoNoNoNoYesYesYesNoNo CVE-2026-43760 Screen Sharing Server An app may be able to access user-sensitive data 8.6HIGH NoNoNoYesNoNoNoNoNoNo CVE-2026-84581 HFS Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory 8.4HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-84535 Automator An app may be able to break out of its sandbox 8.2HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-84516 CUPS Processing a maliciously crafted file may result in unexpected app termination or disclosure of process memory 8.1HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-65415 Kernel A local user may be able to cause unexpected system termination or read kernel memory 8.1HIGH YesNoYesNoNoYesYesYesNoNo CVE-2026-84568 autofs An attacker with control of a network directory server may be able to execute arbitrary code with root privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-84607 AVEVideoEncoder A sandboxed app may be able to execute arbitrary code with kernel privileges 7.8HIGH YesYesYesYesYesYesYesYesNoNo CVE-2026-84631 Bluetooth An app may be able to gain root privileges 7.8HIGH NoNoYesNoNoNoNoNoNoNo CVE-2026-43786 CoreServices An app may be able to gain root privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-84575 CoreUI Processing a maliciously crafted file may lead to unexpected app termination 7.8HIGH YesNoYesYesYesYesYesYesNoNo CVE-2026-43691 CUPS An app may be able to gain root privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-43698 CUPS An app may be able to gain root privileges 7.8HIGH NoNoYesYesNoNoNoNoNoNo CVE-2026-84505 Directory Utility An app may be able to gain root privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-65362 Disk Images An app may be able to gain root privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-64758 ImageIO Processing a maliciously crafted file may lead to unexpected app termination 7.8HIGH NoYesNoNoYesNoNoNoNoNo CVE-2026-43684 Kernel An app may be able to cause unexpected system termination or corrupt kernel memory 7.8HIGH NoYesYesNoYesNoNoNoNoNo CVE-2026-43689 Kernel A malicious app may be able to gain root privileges 7.8HIGH YesYesYesNoNoNoNoYesNoNo CVE-2026-86917 Kernel An app may be able to gain root privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-64712 odproxyd An app may be able to gain root privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-84515 SMB Connecting to a malicious SMB server may lead to kernel memory corruption 7.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-84506 udf An app may be able to execute arbitrary code with kernel privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-64761 Accessibility An app may be able to identify what other apps a user has installed 7.5HIGH YesNoNoNoNoNoNoNoNoNo CVE-2026-86895 CloudKit A local app may be able to read a persistent account identifier 7.5HIGH YesNoNoNoNoYesYesYesNoNo CVE-2026-84563 CUPS An app may be able to cause unexpected system termination 7.5HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-84606 iCloud An app may be able to identify a user across reinstalls 7.5HIGH YesNoYesNoNoNoNoYesNoNo CVE-2026-43661 ImageIO Processing a maliciously crafted image may corrupt process memory 7.5HIGH NoYesNoNoNoNoNoNoNoNo CVE-2026-28969 IOKit An app may be able to cause unexpected system termination 7.5HIGH YesNoYesYesYesYesYesYesNoNo CVE-2026-65343 Kernel A remote attacker may be able to cause unexpected system termination 7.5HIGH NoNoNoNoNoYesYesYesNoNo CVE-2026-65364 Kernel A remote attacker may be able to cause unexpected system termination 7.5HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-86894 libxpc An app may be able to break out of its sandbox 7.5HIGH NoNoYesNoNoNoNoNoNoNo CVE-2026-84543 SMB Connecting to a malicious SMB server may cause unexpected system termination or corrupt kernel memory 7.5HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-84553 smbx A remote attacker may be able to cause a denial-of-service 7.5HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-28930 Spotlight An app may be able to access protected user data 7.5HIGH NoNoNoNoYesNoNoNoNoNo CVE-2026-86904 Watch App An app may be able to track users across apps and websites without permission 7.5HIGH YesYesNoNoNoNoYesNoNoNo CVE-2026-64752 CoreMedia Processing a maliciously crafted image may lead to arbitrary code execution 7.3HIGH YesNoYesNoNoNoNoYesNoNo CVE-2026-84611 SceneKit Processing a maliciously crafted 3D model may lead to memory corruption 7.3HIGH YesYesYesYesYesYesYesYesNoNo CVE-2026-84632 SceneKit Processing a maliciously crafted 3D model may lead to memory corruption 7.3HIGH YesYesYesYesYesYesYesYesNoNo CVE-2026-64736 IOMobileFrameBuffer An app may be able to cause unexpected system termination or corrupt kernel memory 7.1HIGH NoNoNoNoYesYesYesYesNoNo CVE-2026-65349 Kernel An app may be able to cause unexpected system termination or read kernel memory 6.6MEDIUM NoNoNoNoYesYesYesYesNoNo CVE-2026-84537 SMB An app may be able to cause unexpected system termination or corrupt kernel memory 6.6MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-43788 Spotlight Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents 6.6MEDIUM NoNoYesNoNoNoNoNoNoNo CVE-2026-86882 Accelerate Framework Processing a maliciously crafted image may lead to unexpected process termination 6.5MEDIUM YesYesYesYesYesYesYesYesNoNo CVE-2026-84519 AppleDouble Mounting a disk image with maliciously crafted files may lead to unexpected system termination 6.5MEDIUM YesYesYesYesYesNoNoNoNoNo CVE-2026-86879 Baseband A remote attacker may be able to cause a denial-of-service 6.5MEDIUM YesNoNoNoNoNoNoNoNoNo CVE-2026-86885 Baseband An attacker in radio range may be able to cause unexpected system termination 6.5MEDIUM YesNoNoNoNoNoNoNoNoNo CVE-2026-65412 CoreText Processing web content may lead to a denial-of-service 6.5MEDIUM YesYesYesYesYesNoYesYesNoNo CVE-2026-84596 CoreText Processing a maliciously crafted font may result in the disclosure of process memory 6.5MEDIUM YesNoYesNoNoYesYesYesNoNo CVE-2026-84597 FontParser Processing a maliciously crafted font may result in the disclosure of process memory 6.5MEDIUM YesNoYesNoNoYesYesYesNoNo CVE-2022-3437 Heimdal A user in a privileged network position may be able to leak sensitive user information 6.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-28934 HFS Mounting a malicious disk image may cause unexpected system termination 6.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-65347 ImageIO Processing an image may lead to a denial-of-service 6.5MEDIUM NoNoNoNoNoYesYesYesNoNo CVE-2026-65395 ImageIO Processing a maliciously crafted image may result in memory corruption 6.5MEDIUM YesYesYesYesYesYesNoYesNoNo CVE-2026-43687 Kernel Connecting to a malicious NFS server may disclose kernel memory 6.5MEDIUM YesYesYesYesNoYesYesYesNoNo CVE-2026-65330 Kernel An app may be able to cause unexpected system termination or corrupt kernel memory 6.5MEDIUM NoNoNoNoYesYesYesYesNoNo CVE-2026-84538 Kernel A remote attacker may be able to cause a denial-of-service 6.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-84588 Kernel Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory 6.5MEDIUM NoNoYesNoNoNoNoNoNoNo CVE-2026-84487 SceneKit Processing a maliciously crafted file may result in disclosure of process memory 6.5MEDIUM YesYesYesYesYesYesYesYesNoNo CVE-2026-43719 SMB Mounting a maliciously crafted SMB network share may lead to system termination 6.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-65365 SMB Connecting to a malicious SMB share may disclose kernel memory 6.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-84536 SMB Connecting to a malicious SMB server may lead to unexpected system termination 6.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-43677 WebDAV Connecting to a malicious WebDAV server may lead to unexpected app termination 6.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-64715 WebKit Processing maliciously crafted web content may lead to an unexpected process crash 6.5MEDIUM NoNoNoNoNoYesYesYesNoNo CVE-2026-64753 WebKit Processing maliciously crafted web content may disclose sensitive user information 6.5MEDIUM YesNoYesNoNoYesYesYesYesNo CVE-2026-64787 WebKit Processing maliciously crafted web content may lead to an unexpected process termination 6.5MEDIUM NoNoNoNoNoYesYesYesNoNo CVE-2026-64778 WebKit History Visiting a maliciously crafted website may leak sensitive data 6.5MEDIUM NoNoNoNoNoYesYesYesNoNo CVE-2026-84560 Bluetooth An app may gain unauthorized access to Bluetooth 6.1MEDIUM YesNoYesNoNoYesYesYesNoNo CVE-2026-84619 Kernel An app may be able to cause unexpected system termination or write kernel memory 6.1MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-84554 CUPS An attacker in a privileged network position may be able to cause a denial-of-service 5.9MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-43664 Accessibility An app may be able to access sensitive user data 5.5MEDIUM YesYesYesYesYesYesYesNoNoNo CVE-2026-65404 Accounts A malicious application may be able to bypass Privacy preferences 5.5MEDIUM YesNoYesNoNoNoNoNoNoNo CVE-2026-84523 APFS An app may be able to cause unexpected system termination or write kernel memory 5.5MEDIUM YesYesYesYesYesYesYesYesNoNo CVE-2026-84586 Apple Account A malicious application may be able to leak sensitive user information 5.5MEDIUM NoNoYesNoNoNoYesNoNoNo CVE-2026-65407 AppleAVD An app may be able to cause unexpected system termination 5.5MEDIUM YesYesYesYesYesYesYesYesNoNo CVE-2026-84593 AppleKeyStore An app may be able to cause unexpected system termination 5.5MEDIUM YesNoNoNoNoNoNoNoNoNo CVE-2026-43763 ATS An app may be able to read files outside of its sandbox 5.5MEDIUM NoNoNoYesYesNoNoNoNoNo CVE-2026-86905 Authentication Services An app may be able to delete credentials stored in Keychain 5.5MEDIUM YesNoYesNoNoNoNoYesNoNo CVE-2026-43737 CoreMotion An app may be able to access motion data from headphones without user consent 5.5MEDIUM YesYesYesYesYesYesYesNoNoNo CVE-2026-43738 CoreUI Processing a maliciously crafted asset catalog may result in disclosure of process memory 5.5MEDIUM YesNoYesNoNoNoNoNoNoNo CVE-2026-84489 CoreUI An app may be able to cause a denial of service 5.5MEDIUM YesNoYesNoNoNoNoNoNoNo CVE-2026-84534 file_cmds Extracting a maliciously crafted archive may allow an attacker to write arbitrary files 5.5MEDIUM YesYesYesYesYesNoNoYesNoNo CVE-2026-65409 Foundation An app may be able to cause a denial of service 5.5MEDIUM YesYesYesYesYesYesYesYesNoNo CVE-2026-64756 Image Capture An app may be able to access user-sensitive data 5.5MEDIUM YesNoYesYesYesNoNoNoNoNo CVE-2026-64760 IOSurfaceAccelerator An app may be able to leak sensitive kernel state 5.5MEDIUM YesNoYesNoNoYesYesYesNoNo CVE-2026-65401 Kernel An app may be able to cause unexpected system termination 5.5MEDIUM NoNoYesYesNoNoNoNoNoNo CVE-2026-65402 Kernel An app may be able to cause unexpected system termination 5.5MEDIUM YesYesYesYesYesYesYesYesNoNo CVE-2026-65405 Kernel An app may be able to determine kernel memory layout 5.5MEDIUM YesYesYesYesYesYesYesYesNoNo CVE-2026-84517 Kernel An app may be able to cause unexpected system termination 5.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-84521 Kernel An app may be able to cause unexpected system termination 5.5MEDIUM YesYesYesYesYesNoNoYesNoNo CVE-2026-86903 Kernel An app may be able to disclose kernel memory 5.5MEDIUM YesNoYesNoNoYesYesYesNoNo CVE-2026-86883 Managed Configuration An app may be able to access sensitive user data 5.5MEDIUM YesNoNoNoNoNoNoYesNoNo CVE-2026-43741 Messages An app may be able to access protected user data 5.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-84491 Photos Storage An app may be able to access sensitive user data 5.5MEDIUM YesYesYesNoNoYesYesYesNoNo CVE-2026-84576 QuartzCore An app may be able to access sensitive user data 5.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-84555 Sandbox An app may be able to access sensitive user data 5.5MEDIUM NoNoYesNoYesNoNoNoNoNo CVE-2026-65413 SceneKit An app may be able to cause a denial of service 5.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-28937 Terminal An app may be able to access sensitive user data 5.5MEDIUM NoNoYesNoNoNoNoNoNoNo CVE-2026-64718 WebKit Canvas Processing maliciously crafted web content may lead to an unexpected Safari crash 5.5MEDIUM YesYesYesNoNoNoNoYesYesNo CVE-2026-65393 Xcode IDE An app may be able to access user-sensitive data 5.5MEDIUM NoNoYesNoNoNoNoNoNoYes CVE-2026-84617 XPC An app may be able to access sensitive user data 5.5MEDIUM YesYesYesYesYesYesNoNoNoNo CVE-2026-64788 IOGPUFamily Processing maliciously crafted web content may lead to memory corruption 5.4MEDIUM NoNoNoNoNoNoYesYesNoNo CVE-2026-65341 WebKit Processing maliciously crafted web content may lead to memory corruption 5.4MEDIUM NoNoNoNoNoYesYesYesNoNo CVE-2026-34979 CUPS An attacker in a privileged network position may be able to cause a denial-of-service 5.3MEDIUM NoNoYesNoNoNoNoNoNoNo CVE-2026-86876 CoreMedia A sandboxed process may be able to circumvent sandbox restrictions 5.2MEDIUM YesYesYesYesYesNoYesYesNoNo CVE-2026-86889 Security An attacker in a privileged network position may be able to intercept network traffic 4.8MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-84492 Graphics An app may be able to cause unexpected system termination 4.7MEDIUM YesYesYesYesYesYesYesYesNoNo CVE-2026-84630 Kernel An app may be able to cause unexpected system termination 4.7MEDIUM YesYesYesYesYesYesYesYesNoNo CVE-2026-43690 SMB A local user may be able to read kernel memory 4.7MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-84518 Safari A malicious website may be able to determine what apps a user has installed 4.3MEDIUM YesNoYesNoNoNoNoNoYesNo CVE-2026-43795 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-64780 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-64781 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-64784 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-65331 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-65332 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-65333 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-65334 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-65335 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-65336 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-65337 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-65338 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-65340 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-65351 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-64782 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 3.1LOW NoNoNoNoNoNoNoYesNoNo CVE-2026-64779 WebKit Storage Processing maliciously crafted web content may lead to an unexpected Safari crash 3.1LOW NoNoNoNoNoNoNoYesNoNo CVE-2026-86910 APFS An application may be able to access restricted files TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-86888 App Store A local app may be able to read a persistent account identifier TBDTBD YesNoYesYesNoYesYesYesNoNo CVE-2026-84587 AppKit An app may be able to access protected user data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-20683 Apple Account An app may be able to use the Sign In With Apple authentication flow to access the user's Apple Account TBDTBD YesNoYesYesYesNoNoYesNoNo CVE-2026-84601 Apple Intelligence An app may be able to bypass Apple Intelligence security prompts TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-65408 Apple Neural Engine An app may be able to cause unexpected system termination TBDTBD YesYesYesYesYesNoNoNoNoNo CVE-2026-84520 AppleFDEKeyStore A local attacker may be able to cause unexpected system termination or corrupt kernel memory TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-65381 AppleMobileFileIntegrity A malicious app may be able to break out of its sandbox TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84522 Archive Utility An app may be able to access sensitive user data TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-84584 Archive Utility An app may be able to break out of its sandbox TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-65342 ATS An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84525 ATS An app may be able to access user-sensitive data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-65339 Audio An app may be able to leak sensitive user information TBDTBD NoNoNoNoYesYesYesYesNoNo CVE-2026-84583 AuthKit A local app may be able to read a persistent account identifier TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84570 autofs An app may be able to bypass Gatekeeper checks TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-65410 AVEVideoEncoder An app may be able to cause unexpected system termination TBDTBD YesYesYesYesNoYesYesYesNoNo CVE-2026-84616 AVEVideoEncoder An app may be able to cause unexpected system termination TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-65406 BackgroundAssets An app may be able to access sensitive user data TBDTBD YesYesYesYesYesYesNoYesNoNo CVE-2026-86878 Camera An app may be able to access sensitive user data TBDTBD YesNoNoNoNoNoNoNoNoNo CVE-2026-84567 cd9660 An app may be able to cause unexpected system termination TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-86893 CloudKit An app may be able to read device name TBDTBD YesNoNoNoNoYesYesYesNoNo CVE-2026-65399 copyfile An archive may be able to bypass Gatekeeper TBDTBD YesYesYesYesYesNoYesYesNoNo CVE-2026-86891 Core Bluetooth An app may be able to access Bluetooth device information TBDTBD NoNoYesYesYesNoYesNoNoNo CVE-2026-43683 CoreDrag An app may be able to cause unexpected process termination or disclose process memory TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-43789 CoreMedia An app may be able to access user-sensitive data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-65344 CoreMedia Processing a maliciously crafted video file may lead to unexpected app termination TBDTBD YesYesYesYesYesYesNoYesNoNo CVE-2026-43702 CoreMedia Video Toolbox Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory TBDTBD NoYesNoYesYesNoNoNoNoNo CVE-2026-84624 CoreML A sandboxed app may be able to access restricted files TBDTBD YesYesYesYesYesNoNoYesNoNo CVE-2026-84559 CoreServices A malicious application may be able to access restricted files TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84574 CoreServices An app may be able to bypass Privacy preferences TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84511 CoreUI Processing a maliciously crafted asset catalog may lead to unexpected process termination TBDTBD YesNoYesYesYesYesYesYesNoNo CVE-2026-84571 CoreUI Processing a maliciously crafted image may lead to unexpected app termination TBDTBD YesNoYesNoNoYesYesYesNoNo CVE-2026-64790 CUPS An app may be able to gain elevated privileges TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84540 CUPS An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84541 CUPS An application may be able to access restricted files TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84612 DeviceCheck An app may be able to read persistent device identifiers TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84512 Disk Images Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84550 Disk Images An app may be able to cause unexpected system termination TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84552 Disk Images An app may be able to cause unexpected system termination TBDTBD YesYesYesYesYesNoNoNoNoNo CVE-2026-84565 Disk Images Processing a maliciously crafted disk image may lead to unexpected app termination TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84510 exFAT Mounting a maliciously crafted volume may lead to unexpected system termination TBDTBD YesYesYesYesYesNoNoNoNoNo CVE-2026-86900 exFAT Mounting a maliciously crafted exFAT volume may cause unexpected system termination or kernel memory disclosure TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-86901 exFAT Mounting a maliciously crafted exFAT volume may cause unexpected system termination or kernel memory disclosure TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-43785 File Bookmark An app may be able to modify a file it only had permission to read TBDTBD YesNoYesYesYesYesNoYesNoNo CVE-2026-43688 Filters Processing a maliciously crafted file may lead to unexpected app termination TBDTBD YesNoYesNoNoNoNoNoNoNo CVE-2026-84524 FontParser Processing a maliciously crafted font file may lead to unexpected app termination TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84569 Foundation An app may be able to access sensitive user data TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-86911 Foundation A malicious app may be able to bypass clickjacking protections for secure prompts TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-84618 Game Center An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84533 Heimdal An attacker in a privileged network position may be able to modify network traffic TBDTBD YesNoYesNoNoYesYesNoNoNo CVE-2026-64714 ImageIO Processing a maliciously crafted image may lead to a denial-of-service TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-84564 ImageIO Processing a maliciously crafted image may result in disclosure of process memory TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-86869 ImageIO Processing a maliciously crafted image may lead to unexpected app termination TBDTBD NoYesYesNoNoNoNoNoNoNo CVE-2026-43743 IOGPUFamily An app may be able to cause unexpected system termination TBDTBD NoYesNoYesNoNoNoNoNoNo CVE-2026-65398 IOMobileFrameBuffer An app may be able to cause unexpected system termination or corrupt kernel memory TBDTBD YesNoYesNoNoYesYesYesNoNo CVE-2026-65354 iWork A malicious app may be able to break out of its sandbox TBDTBD YesNoYesNoNoNoNoNoNoNo CVE-2026-28935 Kernel An app may be able to cause unexpected system termination or corrupt kernel memory TBDTBD NoNoNoNoYesYesYesYesNoNo CVE-2026-28968 Kernel An app may be able to cause unexpected system termination or corrupt kernel memory TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-43790 Kernel A remote attacker may be able to cause unexpected system termination or corrupt kernel memory TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-65358 Kernel An app may be able to cause unexpected system termination TBDTBD YesNoYesYesYesYesYesYesNoNo CVE-2026-65359 Kernel A local user may be able to cause unexpected system termination or read kernel memory TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-65360 Kernel An app may be able to cause unexpected system termination TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-65369 Kernel A malicious application may bypass Gatekeeper checks TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-65371 Kernel An app may be able to disclose kernel memory TBDTBD NoNoNoNoYesNoNoNoNoNo CVE-2026-65377 Kernel An app may be able to cause unexpected system termination TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84507 Kernel An app may be able to cause unexpected system termination or corrupt kernel memory TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84530 Kernel An app may be able to disclose kernel memory TBDTBD YesYesYesYesNoYesYesYesNoNo CVE-2026-84544 Kernel Connecting to a malicious NFS server may cause unexpected system termination or corrupt kernel memory TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84549 Kernel Connecting to a malicious NFS server may cause unexpected system termination or corrupt kernel memory TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84558 Kernel An app may be able to cause unexpected system termination TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-84561 Kernel An app may be able to cause unexpected system termination or corrupt kernel memory TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84566 Kernel A local attacker may be able to cause unexpected system termination or corrupt kernel memory TBDTBD YesYesYesYesYesNoNoNoNoNo CVE-2026-84602 Kernel An app may be able to cause unexpected system termination TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84622 Kernel An app with root privileges may be able to read uninitialized kernel memory TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84514 Kext Management An app may be able to modify protected parts of the file system TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84556 Keychain Access An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-65382 LaunchServices An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-86870 libarchive Processing a maliciously crafted file may lead to unexpected app termination TBDTBD YesYesYesNoNoNoYesYesNoNo CVE-2026-84577 libxpc An app may be able to bypass sandbox restrictions TBDTBD NoNoYesYesNoNoNoNoNoNo CVE-2026-43787 Mail An attacker in a privileged network position may be able to leak sensitive user information TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84573 Mail An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84628 MediaRemote A sandboxed app may be able to access the System Keychain TBDTBD YesNoYesNoNoYesYesYesNoNo CVE-2026-86924 MobileAccessoryUpdater Connecting a malicious accessory may cause unexpected system termination TBDTBD YesYesYesYesNoNoNoNoNoNo CVE-2026-65411 MobileBackup An app may be able to modify protected parts of the file system TBDTBD YesYesNoNoNoNoNoYesNoNo CVE-2026-84598 MobileBackup An attacker with physical access to a trust-paired device may be able to read and write arbitrary files TBDTBD YesYesNoNoNoNoNoNoNoNo CVE-2026-84497 Model I/O Opening a maliciously crafted file may lead to unexpected process termination TBDTBD YesYesYesYesYesYesNoYesNoNo CVE-2026-84615 Music An app may be able to access sensitive user data TBDTBD YesYesNoNoNoYesNoYesNoNo CVE-2026-43695 NetworkExtension An app may be able to access sensitive user data TBDTBD YesNoYesYesYesYesYesYesNoNo CVE-2026-84585 NetworkExtension An app may be able to access local network devices without user consent TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-84626 NetworkExtension An app may be able to identify what other apps a user has installed TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-86902 NSDocument An app may be able to access sensitive user data TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-84629 Photos Storage An app may be able to fingerprint the user TBDTBD YesNoNoNoNoYesYesYesNoNo CVE-2026-84623 Power Management An app may be able to fingerprint the device TBDTBD YesYesNoNoNoNoNoNoNoNo CVE-2026-84578 quarantine An app may be able to break out of its sandbox TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84580 quarantine An app may be able to break out of its sandbox TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84548 Quick Look Processing a maliciously crafted document may lead to an out-of-bounds read TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-28966 RealityKit Processing a maliciously crafted file may lead to unexpected app termination TBDTBD YesYesYesYesYesYesNoYesNoNo CVE-2026-84532 RealityKit Opening a maliciously crafted file may cause unexpected process termination or disclose process memory TBDTBD YesYesYesYesYesYesNoYesNoNo CVE-2026-65403 Reminders An app may be able to access sensitive user data TBDTBD YesYesYesYesYesNoYesYesNoNo CVE-2026-86897 Safe Browsing An app may be able to access sensitive user data TBDTBD YesYesYesNoNoNoNoYesYesNo CVE-2026-65380 Sandbox An app may be able to access protected user data TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-84551 Sandbox An app may be able to bypass network restrictions TBDTBD YesNoYesNoNoNoYesYesNoNo CVE-2026-84603 Sandbox Profiles An app may be able to access sensitive user data TBDTBD YesNoNoNoNoNoYesYesNoNo CVE-2026-84625 Sandbox Profiles An app may be able to fingerprint the user TBDTBD YesNoYesNoNoNoYesYesNoNo CVE-2026-43697 SceneKit Processing a maliciously crafted 3D file may lead to an out-of-bounds read TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84526 SceneKit Processing a maliciously crafted 3D scene may lead to unexpected process termination TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84546 SceneKit Processing a maliciously crafted 3D model may lead to memory corruption TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84620 SceneKit Processing a maliciously crafted 3D model may lead to memory corruption TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84531 Security Processing maliciously crafted NTLM input may lead to unexpected app termination TBDTBD YesNoYesNoNoNoNoNoNoNo CVE-2026-86881 Security An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84600 Shortcuts A malicious shortcut may be able to send messages without user confirmation TBDTBD YesNoYesNoNoYesYesYesNoNo CVE-2026-86884 Siri An app may be able to access sensitive user data TBDTBD YesNoYesNoNoYesYesNoNoNo CVE-2026-86890 Siri Suggestions An attacker with physical access to a locked device may be able to view sensitive user information TBDTBD YesYesNoNoNoNoNoNoNoNo CVE-2026-65376 SMB An app may be able to cause unexpected system termination TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84509 SMB Connecting to a malicious SMB server may lead to unexpected system termination TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84609 Software Update An app may be able to modify protected system files TBDTBD YesNoYesYesYesYesYesYesNoNo CVE-2026-65361 SoftwareUpdate An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-65378 Spotlight An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84621 Spotlight An app may be able to access sensitive user data TBDTBD YesYesYesYesYesNoNoNoNoNo CVE-2026-86892 SpringBoard An app may be able to cause a denial-of-service TBDTBD YesYesNoNoNoNoNoYesNoNo CVE-2026-65345 Storage An app may be able to access user-sensitive data TBDTBD YesYesYesYesYesNoNoNoNoNo CVE-2026-65348 Storage An app may be able to modify protected parts of the file system TBDTBD YesYesYesYesYesNoNoNoNoNo CVE-2026-43791 StorageKit An app may be able to read arbitrary files TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84513 Symptom Framework A malicious application may be able to determine a user's current location TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-65383 System Settings An app may bypass Gatekeeper checks TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-86909 System Settings An app may be able to bypass Gatekeeper checks TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-84527 TCC An app may be able to access sensitive user data TBDTBD YesNoYesYesYesYesYesYesNoNo CVE-2026-84589 TCC An app may be able to modify Privacy preferences TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-86886 TCC An app may be able to modify protected system files TBDTBD YesYesNoNoNoNoYesNoNoNo CVE-2026-65329 Telephony An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic TBDTBD YesNoNoNoNoNoNoNoNoNo CVE-2026-86887 Time Zone An app may be able to bypass certain Privacy preferences TBDTBD YesYesNoNoNoNoNoYesNoNo CVE-2026-43696 Touch Bar An app may be able to capture Touch Bar content without authorization TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-84572 udf An app may be able to cause unexpected system termination or read kernel memory TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-28899 WebDAV An app may bypass Gatekeeper checks TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-65375 WebDAV An app may be able to cause unexpected system termination TBDTBD NoNoYesNoYesNoNoNoNoNo CVE-2026-84635 WebKit Processing maliciously crafted web content may lead to an unexpected process termination TBDTBD YesNoYesNoNoYesYesYesYesNo CVE-2026-86898 WebKit Opening a maliciously crafted webarchive file may lead to universal cross-site scripting TBDTBD YesNoYesNoNoNoNoYesYesNo CVE-2026-84636 Wi-Fi Connectivity An app may be able to access sensitive user data TBDTBD YesNoNoNoNoYesYesYesNoNo CVE-2026-43674 Wi-Fi3 An attacker with physical access to an unlocked device may be able to view Wi-Fi passwords without authentication TBDTBD YesNoNoNoNoNoNoNoNoNo

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.thezdi.com/blog/2026/9/16/the-apple-security-update-review-for-september-2026