Apple Security Advisories · March 2026 — Apple Security Advisories
81 advisories 81 CVEs

Apple-vendor CVEs for 2026-03. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2026-28862

macOSActive exploitation (sightings)HIGH2026-03-24

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access user-sensitive data.

CVEs:CVE-2026-28862

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28880

visionOSActive exploitation (sightings)MEDIUM2026-03-24

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4. An app may be able to enumerate a...

CVEs:CVE-2026-28880

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
visionos affected apple
Upstream advisory

CVE-2026-28865

visionOSActive exploitation (sightings)HIGH2026-03-24

An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An...

CVEs:CVE-2026-28865

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-20690

visionOSActive exploitation (sightings)MEDIUM2026-03-24

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26....

CVEs:CVE-2026-20690

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-20664

visionOSActive exploitation (sightings)HIGH2026-03-24

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may lead to an unexpected process crash.

CVEs:CVE-2026-20664

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
visionos affected apple
Upstream advisory

CVE-2026-28886

visionOSActive exploitation (sightings)MEDIUM2026-03-24

A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4....

CVEs:CVE-2026-28886

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-28859

visionOSActive exploitation (sightings)HIGH2026-03-24

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. A malicious website may be able to process restricted web content outside the...

CVEs:CVE-2026-28859

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-20665

visionOSActive exploitation (sightings)CRITICAL2026-03-24

This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. Processing maliciously crafted web content...

CVEs:CVE-2026-20665

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-28857

visionOSActive exploitation (sightings)HIGH2026-03-24

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may lead to an unexpected process crash.

CVEs:CVE-2026-28857

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
visionos affected apple
Upstream advisory

CVE-2026-20657

visionOSActive exploitation (sightings)CRITICAL2026-03-24

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4. Parsing a maliciously crafte...

CVEs:CVE-2026-20657

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2026-28858

iPadOSActive exploitation (sightings)CRITICAL2026-03-24

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote user may be able to cause unexpected system termination or corrupt kernel memory.

CVEs:CVE-2026-28858

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2026-28875

iPadOSActive exploitation (sightings)CRITICAL2026-03-24

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote attacker may be able to cause a denial-of-service.

CVEs:CVE-2026-28875

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2026-28838

macOSActive exploitation (sightings)MEDIUM2026-03-24

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to break out of its sandbox.

CVEs:CVE-2026-28838

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28876

visionOSActive exploitation (sightings)HIGH2026-03-24

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4. A...

CVEs:CVE-2026-28876

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
visionos affected apple
Upstream advisory

CVE-2026-28835

macOSActive exploitation (sightings)CRITICAL2026-03-24

A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. Mounting a maliciously crafted SMB network share may lead to system termination.

CVEs:CVE-2026-28835

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28879

visionOSActive exploitation (sightings)CRITICAL2026-03-24

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. Pr...

CVEs:CVE-2026-28879

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-28874

iPadOSActive exploitation (sightings)HIGH2026-03-24

The issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote attacker may cause an unexpected app termination.

CVEs:CVE-2026-28874

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2026-20692

iPadOSActive exploitation (sightings)MEDIUM2026-03-24

A privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. "Hide IP Address" and "Block All Remote Content" may not apply to al...

CVEs:CVE-2026-20692

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2026-20701

macOSActive exploitation (sightings)HIGH2026-03-24

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to connect to a network share without user consent.

CVEs:CVE-2026-20701

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-20693

macOSActive exploitation (sightings)MEDIUM2026-03-24

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An attacker with root privileges may be able to delete protected system files.

CVEs:CVE-2026-20693

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-20697

macOSActive exploitation (sightings)MEDIUM2026-03-24

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access sensitive user data.

CVEs:CVE-2026-20697

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28818

macOSActive exploitation (sightings)MEDIUM2026-03-24

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access sensitive user data.

CVEs:CVE-2026-28818

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28839

macOSActive exploitation (sightings)MEDIUM2026-03-24

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access sensitive user data.

CVEs:CVE-2026-28839

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28842

macOSActive exploitation (sightings)CRITICAL2026-03-24

The issue was addressed with improved bounds checks. This issue is fixed in macOS Tahoe 26.4. A buffer overflow may result in memory corruption and unexpected app termination.

CVEs:CVE-2026-28842

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28825

macOSActive exploitation (sightings)CRITICAL2026-03-24

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to modify protected parts of the file system.

CVEs:CVE-2026-28825

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-20643

iPadOSActive exploitation (sightings)MEDIUM2026-03-17

A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS, iPadOS, and macOS, Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Taho...

CVEs:CVE-2026-20643

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2026-28824

macOSActive exploitation (sightings)MEDIUM2026-03-24

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access sensitive user data.

CVEs:CVE-2026-28824

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28828

macOSActive exploitation (sightings)MEDIUM2026-03-24

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access sensitive user data.

CVEs:CVE-2026-28828

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28837

macOSActive exploitation (sightings)HIGH2026-03-24

A logic issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.

CVEs:CVE-2026-28837

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28844

macOSActive exploitation (sightings)MEDIUM2026-03-24

A file access issue was addressed with improved input validation. This issue is fixed in macOS Tahoe 26.4. An attacker may gain access to protected parts of the file system.

CVEs:CVE-2026-28844

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-20687

iPadOSActive exploitation (sightings)CRITICAL2026-03-24

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Tahoe 26.4, tvOS 26.4, watchOS 26.4. An app may be able to cause unexpected...

CVEs:CVE-2026-20687

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2026-20698

visionOSActive exploitation (sightings)HIGH2026-03-24

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to cause unexpected system termination or corrupt kernel memory.

CVEs:CVE-2026-20698

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-20695

macOSActive exploitation (sightings)HIGH2026-03-24

An information disclosure issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to determine kernel memory layout.

CVEs:CVE-2026-20695

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-20631

macOSActive exploitation (sightings)HIGH2026-03-24

A logic issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.4. A user may be able to elevate privileges.

CVEs:CVE-2026-20631

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28823

macOSActive exploitation (sightings)MEDIUM2026-03-24

A path handling issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26.4. An app with root privileges may be able to delete protected system files.

CVEs:CVE-2026-28823

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28827

macOSActive exploitation (sightings)CRITICAL2026-03-24

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to break out of its sandbox.

CVEs:CVE-2026-28827

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28856

visionOSActive exploitation (sightings)MEDIUM2026-03-24

The issue was addressed with improved authentication. This issue is fixed in iOS 26.4 and iPadOS 26.4, visionOS 26.4, watchOS 26.4. An attacker with physical access to a locked device may be able to view sensitive user information.

CVEs:CVE-2026-28856

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-20691

visionOSActive exploitation (sightings)MEDIUM2026-03-24

An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. A maliciously crafted webpage may be able to fingerprint the user.

CVEs:CVE-2026-20691

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-20688

visionOSActive exploitation (sightings)CRITICAL2026-03-24

A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4. An app may be able to break out of its sandbox.

CVEs:CVE-2026-20688

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
visionos affected apple
Upstream advisory

CVE-2026-28833

visionOSActive exploitation (sightings)MEDIUM2026-03-24

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. An app may be able to enumerate a user's installed apps.

CVEs:CVE-2026-28833

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
visionos affected apple
Upstream advisory

CVE-2026-28866

iPadOSActive exploitation (sightings)MEDIUM2026-03-24

This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access sensitive user data.

CVEs:CVE-2026-28866

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2026-28867

visionOSActive exploitation (sightings)MEDIUM2026-03-24

This issue was addressed with improved authentication. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to leak sensitive k...

CVEs:CVE-2026-28867

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-28816

macOSActive exploitation (sightings)MEDIUM2026-03-24

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to delete files for which it does not have permission.

CVEs:CVE-2026-28816

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28852

visionOSActive exploitation (sightings)CRITICAL2026-03-24

A stack overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to cause a ...

CVEs:CVE-2026-28852

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-20633

macOSActive exploitation (sightings)HIGH2026-03-24

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access user-sensitive data.

CVEs:CVE-2026-20633

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28821

macOSActive exploitation (sightings)HIGH2026-03-24

A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to gain ele...

CVEs:CVE-2026-28821

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43534

iPadOSActive exploitation (sightings)MEDIUM2026-03-24

A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.2 and iPadOS 26.2. A user with physical access to an iOS device may be able to bypass Activation Lock.

CVEs:CVE-2025-43534

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2026-28822

visionOSActive exploitation (sightings)MEDIUM2026-03-24

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An attacker may be able to cause u...

CVEs:CVE-2026-28822

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-28832

macOSActive exploitation (sightings)HIGH2026-03-24

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to disclose kernel memory.

CVEs:CVE-2026-28832

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28882

visionOSActive exploitation (sightings)MEDIUM2026-03-24

This issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to enumerate a user's installed apps.

CVEs:CVE-2026-28882

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-28868

visionOSActive exploitation (sightings)MEDIUM2026-03-24

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. An app may be able to d...

CVEs:CVE-2026-28868

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-20607

macOSActive exploitation (sightings)MEDIUM2026-03-24

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access protected user data.

CVEs:CVE-2026-20607

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28895

iPadOSActive exploitation (sightings)MEDIUM2026-03-24

The issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4. An attacker with physical access to an iOS device with Stolen Device Protection enabled may be able to access biometrics-gated Protected Apps with the passcode.

CVEs:CVE-2026-28895

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2026-28881

macOSActive exploitation (sightings)HIGH2026-03-24

A privacy issue was addressed by moving sensitive data. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.

CVEs:CVE-2026-28881

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28831

macOSActive exploitation (sightings)MEDIUM2026-03-24

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access sensitive user data.

CVEs:CVE-2026-28831

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28892

macOSActive exploitation (sightings)MEDIUM2026-03-24

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to modify protected parts of the file system.

CVEs:CVE-2026-28892

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28826

macOSActive exploitation (sightings)MEDIUM2026-03-24

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. A malicious app may be able to break out of its sandbox.

CVEs:CVE-2026-28826

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28829

macOSActive exploitation (sightings)MEDIUM2026-03-24

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to modify protected parts of the file system.

CVEs:CVE-2026-28829

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28864

visionOSActive exploitation (sightings)LOW2026-03-24

This issue was addressed with improved permissions checking. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. A local attacker may g...

CVEs:CVE-2026-28864

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-28841

macOSActive exploitation (sightings)CRITICAL2026-03-24

A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Tahoe 26.4. A buffer overflow may result in memory corruption and unexpected app termination.

CVEs:CVE-2026-28841

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28817

macOSActive exploitation (sightings)HIGH2026-03-24

A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. A sandboxed process may be able to circumvent sandbox restrictions.

CVEs:CVE-2026-28817

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28870

visionOSActive exploitation (sightings)HIGH2026-03-24

An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to access sensitive user data.

CVEs:CVE-2026-28870

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-28888

macOSActive exploitation (sightings)CRITICAL2026-03-24

A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to gain root privileges.

CVEs:CVE-2026-28888

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28834

macOSActive exploitation (sightings)MEDIUM2026-03-24

A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-28834

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28891

macOSActive exploitation (sightings)HIGH2026-03-24

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to break out of its sandbox.

CVEs:CVE-2026-28891

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-20684

macOSActive exploitation (sightings)LOW2026-03-24

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.4. An app may bypass Gatekeeper checks.

CVEs:CVE-2026-20684

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28845

macOSActive exploitation (sightings)MEDIUM2026-03-24

An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.4. An app may be able to access protected user data.

CVEs:CVE-2026-28845

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28893

macOSActive exploitation (sightings)LOW2026-03-24

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Tahoe 26.4. A document may be written to a temporary file when using print preview.

CVEs:CVE-2026-28893

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28889

XcodeActive exploitation (sightings)HIGH2026-03-24

A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 26.4. An app may be able to read arbitrary files as root.

CVEs:CVE-2026-28889

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple
Upstream advisory

CVE-2026-28890

XcodeActive exploitation (sightings)MEDIUM2026-03-24

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 26.4. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-28890

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple
Upstream advisory

CVE-2026-28878

visionOSPoC exploitHIGH2026-03-24

A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.7, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be ...

CVEs:CVE-2026-28878

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-28894

iPadOSPoC exploitHIGH2026-03-24

A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. A remote attacker may be able to cause a denial-of-service.

CVEs:CVE-2026-28894

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2026-28863

visionOSPoC exploitMEDIUM2026-03-24

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.4 and iPadOS 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to fingerprint the user.

CVEs:CVE-2026-28863

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-28860

visionOSPoC exploitHIGH2026-03-24

The issue was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. A local attacker...

CVEs:CVE-2026-28860

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-28861

visionOSPoC exploitMEDIUM2026-03-24

A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. A malicious website may be able to access script message handlers i...

CVEs:CVE-2026-28861

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
visionos affected apple
Upstream advisory

CVE-2026-20632

macOSPoC exploitMEDIUM2026-03-24

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.

CVEs:CVE-2026-20632

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28871

iPadOSPoC exploitCRITICAL2026-03-24

A logic issue was addressed with improved checks. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4. Visiting a maliciously crafted website may lead to a cross-site scripting attack.

CVEs:CVE-2026-28871

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
Upstream advisory

CVE-2026-28820

macOSPoC exploitMEDIUM2026-03-24

This issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.

CVEs:CVE-2026-28820

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28877

visionOSPoC exploitMEDIUM2026-03-24

An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. An app may be ...

CVEs:CVE-2026-28877

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-20670

macOSPoC exploitMEDIUM2026-03-25

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to access sensitive user data.

CVEs:CVE-2026-20670

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-20696

macOSEPSS <= 49%MEDIUM2026-03-24

An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.

CVEs:CVE-2026-20696

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.