Apple Security Advisories · July 2026 — Apple Security Advisories
165 advisories 165 CVEs

Apple-vendor CVEs for 2026-07. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2026-39875

macOSPoC exploitCRITICAL2026-07-27

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.

CVEs:CVE-2026-39875

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64747

visionOSPoC exploitCRITICAL2026-07-27

A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to execute arbitrary...

CVEs:CVE-2026-64747

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-64725

visionOSPoC exploitCRITICAL2026-07-27

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause ...

CVEs:CVE-2026-64725

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-43813

visionOSPoC exploitCRITICAL2026-07-27

A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A maliciously crafted app may be able to bypass code signing enforcement.

CVEs:CVE-2026-43813

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-43803

visionOSCoalition ESS < 30%CRITICAL2026-07-27

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote attacker may be abl...

CVEs:CVE-2026-43803

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-43810

visionOSCoalition ESS < 30%CRITICAL2026-07-27

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote user may be able to cause unexpected s...

CVEs:CVE-2026-43810

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-43807

visionOSCoalition ESS < 30%CRITICAL2026-07-27

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious accessory may be able...

CVEs:CVE-2026-43807

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-64696

macOSCoalition ESS < 30%CRITICAL2026-07-27

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.

CVEs:CVE-2026-64696

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64695

macOSCoalition ESS < 30%CRITICAL2026-07-27

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.

CVEs:CVE-2026-64695

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43682

macOSCoalition ESS < 30%CRITICAL2026-07-27

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.

CVEs:CVE-2026-43682

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43777

macOSCoalition ESS < 30%HIGH2026-07-27

This issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote attacker may be able to cause a denial of service.

CVEs:CVE-2026-43777

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43769

visionOSCoalition ESS < 30%CRITICAL2026-07-27

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpect...

CVEs:CVE-2026-43769

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-64731

macOSCoalition ESS < 30%CRITICAL2026-07-27

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox.

CVEs:CVE-2026-64731

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64733

visionOSCoalition ESS < 30%CRITICAL2026-07-27

This issue was addressed with improved data protection. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to fingerprint the user.

CVEs:CVE-2026-64733

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-43799

visionOSCoalition ESS < 30%CRITICAL2026-07-27

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unex...

CVEs:CVE-2026-43799

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-64700

visionOSCoalition ESS < 30%CRITICAL2026-07-27

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unex...

CVEs:CVE-2026-64700

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-43822

visionOSCoalition ESS < 30%CRITICAL2026-07-27

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unex...

CVEs:CVE-2026-43822

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-43778

visionOSCoalition ESS < 30%CRITICAL2026-07-27

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unex...

CVEs:CVE-2026-43778

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-64771

visionOSCoalition ESS < 30%CRITICAL2026-07-27

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination ...

CVEs:CVE-2026-64771

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2026-64767

macOSCoalition ESS < 30%CRITICAL2026-07-27

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.

CVEs:CVE-2026-64767

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64704

macOSCoalition ESS < 30%CRITICAL2026-07-27

A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-64704

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43750

macOSCoalition ESS < 30%CRITICAL2026-07-27

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.

CVEs:CVE-2026-43750

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64770

visionOSCoalition ESS < 30%CRITICAL2026-07-27

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause une...

CVEs:CVE-2026-64770

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2026-64769

visionOSCoalition ESS < 30%CRITICAL2026-07-27

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause une...

CVEs:CVE-2026-64769

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2026-64774

visionOSCoalition ESS < 30%CRITICAL2026-07-27

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected ...

CVEs:CVE-2026-64774

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2026-64726

visionOSCoalition ESS < 30%CRITICAL2026-07-27

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker in physical proximity may be able to corrupt process memory.

CVEs:CVE-2026-64726

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-43812

visionOSCoalition ESS < 30%CRITICAL2026-07-27

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-43812

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2026-43814

iPadOSCoalition ESS < 30%CRITICAL2026-07-27

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-43814

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2026-64729

visionOSCoalition ESS < 30%CRITICAL2026-07-27

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-64729

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-28928

iPadOSCoalition ESS < 30%CRITICAL2026-07-27

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-28928

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2026-43809

macOSCoalition ESS < 30%CRITICAL2026-07-27

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-43809

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64697

macOSCoalition ESS < 30%CRITICAL2026-07-27

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.

CVEs:CVE-2026-64697

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43793

macOSCoalition ESS < 30%CRITICAL2026-07-27

An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-43793

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43802

macOSCoalition ESS < 30%CRITICAL2026-07-27

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-43802

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43773

macOSCoalition ESS < 30%CRITICAL2026-07-27

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel m...

CVEs:CVE-2026-43773

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43694

macOSCoalition ESS < 30%CRITICAL2026-07-27

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or write kernel memory.

CVEs:CVE-2026-43694

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64698

macOSCoalition ESS < 30%CRITICAL2026-07-27

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or read kernel memory.

CVEs:CVE-2026-64698

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43764

macOSCoalition ESS < 30%CRITICAL2026-07-27

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-43764

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64694

macOSCoalition ESS < 30%CRITICAL2026-07-27

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-64694

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64772

visionOSCoalition ESS < 30%CRITICAL2026-07-27

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application ...

CVEs:CVE-2026-64772

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2026-64703

macOSCoalition ESS < 30%CRITICAL2026-07-27

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause a denial-of-service.

CVEs:CVE-2026-64703

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64746

visionOSCoalition ESS < 30%CRITICAL2026-07-27

An authorization issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. An app may be able to add contacts without user authorization.

CVEs:CVE-2026-64746

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-64735

visionOSCoalition ESS < 30%MEDIUM2026-07-27

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote attacker m...

CVEs:CVE-2026-64735

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-43818

iPadOSCoalition ESS < 30%CRITICAL2026-07-27

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Processing a maliciously crafted image may lead to arbitrary code execution.

CVEs:CVE-2026-43818

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2026-43779

macOSCoalition ESS < 30%CRITICAL2026-07-27

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to intercept network connections intended for another process.

CVEs:CVE-2026-43779

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64702

macOSCoalition ESS < 30%CRITICAL2026-07-27

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to break out of its sandbox.

CVEs:CVE-2026-64702

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64738

macOSCoalition ESS < 30%CRITICAL2026-07-27

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox.

CVEs:CVE-2026-64738

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64775

visionOSCoalition ESS < 30%CRITICAL2026-07-27

A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause...

CVEs:CVE-2026-64775

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-64739

visionOSCoalition ESS < 30%CRITICAL2026-07-27

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker may be able to c...

CVEs:CVE-2026-64739

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-64727

tvOSCoalition ESS < 30%CRITICAL2026-07-27

A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26.6, tvOS 26.6. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-64727

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
tvos affected apple
Upstream advisory

CVE-2026-43748

macOSCoalition ESS < 30%CRITICAL2026-07-27

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-43748

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64691

macOSCoalition ESS < 30%CRITICAL2026-07-27

A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-64691

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64730

visionOSCoalition ESS < 30%MEDIUM2026-07-27

The issue was addressed with improved UI. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Visiting a website that frames malicious content may lead to UI spoofing.

CVEs:CVE-2026-64730

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-43730

visionOSCoalition ESS < 30%CRITICAL2026-07-27

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to fingerprint the user.

CVEs:CVE-2026-43730

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-64720

iPadOSCoalition ESS < 30%CRITICAL2026-07-27

A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-64720

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2026-64751

visionOSCoalition ESS < 30%CRITICAL2026-07-27

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel m...

CVEs:CVE-2026-64751

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-64713

visionOSCoalition ESS < 30%HIGH2026-07-27

This issue was addressed with improved checks. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Websites may know if the user has visited a given link.

CVEs:CVE-2026-64713

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-43757

macOSCoalition ESS < 30%CRITICAL2026-07-27

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-43757

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-39873

macOSCoalition ESS < 30%CRITICAL2026-07-27

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Connecting to a malicious SMB server may lead to unexpected system termination.

CVEs:CVE-2026-39873

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43710

macOSCoalition ESS < 30%CRITICAL2026-07-27

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An attacker may be able to cause unexpected system termination or corrupt kernel memory.

CVEs:CVE-2026-43710

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64762

macOSCoalition ESS < 30%CRITICAL2026-07-27

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-64762

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28982

macOSCoalition ESS < 30%CRITICAL2026-07-27

A race condition was addressed with improved locking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.

CVEs:CVE-2026-28982

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64768

visionOSCoalition ESS < 30%HIGH2026-07-27

An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may cause an unexpected ...

CVEs:CVE-2026-64768

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2026-43821

visionOSCoalition ESS < 30%MEDIUM2026-07-27

An access issue was addressed with improved access restrictions. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to read files outside of its sandbox.

CVEs:CVE-2026-43821

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-43804

visionOSCoalition ESS < 30%HIGH2026-07-27

This issue was addressed through improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6. Visiting a website may lead to an app denial-of-service.

CVEs:CVE-2026-43804

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
visionos affected apple
Upstream advisory

CVE-2026-28911

macOSCoalition ESS < 30%CRITICAL2026-07-27

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to corrupt memory of a system process.

CVEs:CVE-2026-28911

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64719

visionOSCoalition ESS < 30%HIGH2026-07-27

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an...

CVEs:CVE-2026-64719

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-64743

visionOSCoalition ESS < 30%MEDIUM2026-07-27

An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.

CVEs:CVE-2026-64743

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-28931

iPadOSCoalition ESS < 30%CRITICAL2026-07-27

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. Connecting to a malicious NFS server may lead to kernel memory corruption.

CVEs:CVE-2026-28931

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2026-43805

iPadOSCoalition ESS < 30%CRITICAL2026-07-27

A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write ...

CVEs:CVE-2026-43805

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
watchos affected apple
Upstream advisory

CVE-2026-64728

visionOSCoalition ESS < 30%MEDIUM2026-07-27

A permissions issue was addressed with improved validation. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Maliciously crafted web content may violate iframe sandboxing policy.

CVEs:CVE-2026-64728

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-43792

macOSCoalition ESS < 30%MEDIUM2026-07-27

An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.6, macOS Tahoe 26.6. An app may be able to access sensitive user data.

CVEs:CVE-2026-43792

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
safari affected apple
Upstream advisory

CVE-2026-43760

macOSCoalition ESS < 30%HIGH2026-07-27

An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access user-sensitive data.

CVEs:CVE-2026-43760

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64757

visionOSCoalition ESS < 30%CRITICAL2026-07-27

A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Sa...

CVEs:CVE-2026-64757

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-64783

visionOSCoalition ESS < 30%CRITICAL2026-07-27

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safa...

CVEs:CVE-2026-64783

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-64742

visionOSCoalition ESS < 30%MEDIUM2026-07-27

This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 26.6 and iPadOS 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.

CVEs:CVE-2026-64742

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-43728

macOSCoalition ESS < 30%HIGH2026-07-27

This issue was addressed through improved state management. This issue is fixed in macOS Tahoe 26.6. An attacker may be able to modify the state of the Keychain.

CVEs:CVE-2026-43728

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43753

iPadOSCoalition ESS < 30%MEDIUM2026-07-27

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An attacker with physical access to a locked device may be able to view sen...

CVEs:CVE-2026-43753

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2026-64740

iPadOSCoalition ESS < 30%CRITICAL2026-07-27

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6. A malicious app may be able to brea...

CVEs:CVE-2026-64740

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
Upstream advisory

CVE-2026-43766

macOSCoalition ESS < 30%MEDIUM2026-07-27

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An attacker with physical access to a locked device may be able to view sensitive user information.

CVEs:CVE-2026-43766

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43776

iPadOSCoalition ESS < 30%CRITICAL2026-07-27

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execu...

CVEs:CVE-2026-43776

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2026-28981

macOSCoalition ESS < 30%CRITICAL2026-07-27

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Processing a maliciously crafted image may lead to arbitrary code execution.

CVEs:CVE-2026-28981

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43698

macOSCoalition ESS < 30%CRITICAL2026-07-27

An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to gain root privileges.

CVEs:CVE-2026-43698

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43749

macOSCoalition ESS < 30%CRITICAL2026-07-27

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.

CVEs:CVE-2026-43749

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64732

iPadOSCoalition ESS < 30%MEDIUM2026-07-27

This issue was addressed through improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6. An attacker with physical access may be able to access sensitive user data during iPhone Mirroring.

CVEs:CVE-2026-64732

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2026-43772

macOSCoalition ESS < 30%HIGH2026-07-27

A path traversal issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to break out of its sandbox.

CVEs:CVE-2026-43772

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43723

visionOSCoalition ESS < 30%CRITICAL2026-07-27

A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to gain root privileges.

CVEs:CVE-2026-43723

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-64722

iPadOSCoalition ESS < 30%CRITICAL2026-07-27

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a 3D model may result in disclosure of process memory.

CVEs:CVE-2026-64722

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2026-43771

macOSCoalition ESS < 30%CRITICAL2026-07-27

A stack overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause a denial-of-service.

CVEs:CVE-2026-43771

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43765

macOSCoalition ESS < 30%MEDIUM2026-07-27

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to modify protected parts of the file system.

CVEs:CVE-2026-43765

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28912

macOSCoalition ESS < 30%HIGH2026-07-27

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A user may be able to elevate privileges.

CVEs:CVE-2026-28912

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64699

macOSCoalition ESS < 30%MEDIUM2026-07-27

A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to disclose kernel memory.

CVEs:CVE-2026-64699

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64745

macOSCoalition ESS < 30%LOW2026-07-27

This issue was addressed with additional restrictions on the lock screen. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A person with physical access to a locked device may be able to access contacts and photos.

CVEs:CVE-2026-64745

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43733

iPadOSCoalition ESS < 30%HIGH2026-07-27

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a maliciously crafted image may corrupt process memory.

CVEs:CVE-2026-43733

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2026-64734

visionOSCoalition ESS < 30%HIGH2026-07-27

The issue was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted contact may leak sensitive data.

CVEs:CVE-2026-64734

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-64716

visionOSCoalition ESS < 30%HIGH2026-07-27

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted image may corr...

CVEs:CVE-2026-64716

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-28973

iPadOSCoalition ESS < 30%CRITICAL2026-07-27

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, watchOS 26.6. A malicious app may be able to break out of its sandbox.

CVEs:CVE-2026-28973

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
watchos affected apple
Upstream advisory

CVE-2026-43729

visionOSCoalition ESS < 30%HIGH2026-07-27

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. Processing a maliciously crafted image may corrupt process memory.

CVEs:CVE-2026-43729

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2026-43780

visionOSCoalition ESS < 30%CRITICAL2026-07-27

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted tex...

CVEs:CVE-2026-43780

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-64744

macOSCoalition ESS < 30%HIGH2026-07-27

An information leakage was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to disclose kernel memory.

CVEs:CVE-2026-64744

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-39877

macOSCoalition ESS < 30%CRITICAL2026-07-27

A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to disclose kernel memory.

CVEs:CVE-2026-39877

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43800

iPadOSCoalition ESS < 30%HIGH2026-07-27

An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.

CVEs:CVE-2026-43800

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2026-64710

macOSCoalition ESS < 30%HIGH2026-07-27

A privacy issue was addressed by removing sensitive data. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to leak sensitive user information.

CVEs:CVE-2026-64710

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43738

macOSCoalition ESS < 30%MEDIUM2026-07-27

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. Processing a maliciously crafted asset catalog may result in disclosure of process memory.

CVEs:CVE-2026-43738

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64692

visionOSCoalition ESS < 30%HIGH2026-07-27

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause a denia...

CVEs:CVE-2026-64692

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-43774

macOSCoalition ESS < 30%MEDIUM2026-07-27

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access sensitive user data.

CVEs:CVE-2026-43774

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43754

macOSCoalition ESS < 30%HIGH2026-07-27

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to leak sensitive kernel state.

CVEs:CVE-2026-43754

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64721

visionOSCoalition ESS < 30%MEDIUM2026-07-27

This issue was addressed through improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive use...

CVEs:CVE-2026-64721

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-64741

visionOSCoalition ESS < 30%MEDIUM2026-07-27

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and iPadOS 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to read a persistent device identifier.

CVEs:CVE-2026-64741

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-64766

visionOSCoalition ESS < 30%CRITICAL2026-07-27

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted fil...

CVEs:CVE-2026-64766

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-43801

visionOSCoalition ESS < 30%MEDIUM2026-07-27

This issue was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.

CVEs:CVE-2026-43801

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-64764

visionOSCoalition ESS < 30%CRITICAL2026-07-27

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously cra...

CVEs:CVE-2026-64764

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-64709

visionOSCoalition ESS < 30%MEDIUM2026-07-27

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to disclose kernel memory.

CVEs:CVE-2026-64709

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-64765

visionOSCoalition ESS < 30%CRITICAL2026-07-27

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted fil...

CVEs:CVE-2026-64765

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-43796

visionOSCoalition ESS < 30%MEDIUM2026-07-27

This issue was addressed with improved data protection. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.

CVEs:CVE-2026-43796

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-43714

visionOSCoalition ESS < 30%MEDIUM2026-07-27

The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. A malicious app may be able to access protected user data.

CVEs:CVE-2026-43714

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-43758

watchOSCoalition ESS < 30%MEDIUM2026-07-27

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, watchOS 26.6. An app may be able to access sensitive user data.

CVEs:CVE-2026-43758

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
watchos affected apple
Upstream advisory

CVE-2026-64763

visionOSCoalition ESS < 30%CRITICAL2026-07-27

An out-of-bounds write issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously c...

CVEs:CVE-2026-64763

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-64708

macOSCoalition ESS < 30%MEDIUM2026-07-27

A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may bypass Gatekeeper checks.

CVEs:CVE-2026-64708

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28932

macOSCoalition ESS < 30%CRITICAL2026-07-27

A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause a denial of service.

CVEs:CVE-2026-28932

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43768

macOSCoalition ESS < 30%MEDIUM2026-07-27

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-43768

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43759

watchOSCoalition ESS < 30%MEDIUM2026-07-27

An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.6, watchOS 26.6. An app may be able to access sensitive user data.

CVEs:CVE-2026-43759

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
watchos affected apple
Upstream advisory

CVE-2026-43797

iPadOSCoalition ESS < 30%MEDIUM2026-07-27

This issue was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6. An app may be able to access information about a user's contacts.

CVEs:CVE-2026-43797

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2026-28896

macOSCoalition ESS < 30%HIGH2026-07-27

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An attacker may be able to cause unexpected system termination or read kernel memory.

CVEs:CVE-2026-28896

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43681

macOSCoalition ESS < 30%HIGH2026-07-27

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A local user may be able to read kernel memory.

CVEs:CVE-2026-43681

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43817

visionOSCoalition ESS < 30%MEDIUM2026-07-27

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-43817

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-43744

visionOSCoalition ESS < 30%CRITICAL2026-07-27

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing an audio stream i...

CVEs:CVE-2026-43744

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-43816

visionOSCoalition ESS < 30%CRITICAL2026-07-27

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-43816

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-64724

visionOSCoalition ESS < 30%HIGH2026-07-27

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker on the local network may be able to...

CVEs:CVE-2026-64724

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-64693

visionOSCoalition ESS < 30%HIGH2026-07-27

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted image may ...

CVEs:CVE-2026-64693

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-43739

visionOSCoalition ESS < 30%CRITICAL2026-07-27

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-43739

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-28945

macOSCoalition ESS < 30%HIGH2026-07-27

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to bypass network restrictions.

CVEs:CVE-2026-28945

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43673

visionOSCoalition ESS < 30%HIGH2026-07-27

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted audio file may...

CVEs:CVE-2026-43673

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
macOS affected Apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-43711

visionOSCoalition ESS < 30%CRITICAL2026-07-27

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafte...

CVEs:CVE-2026-43711

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-64749

visionOSCoalition ESS < 30%HIGH2026-07-27

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, visionOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.

CVEs:CVE-2026-64749

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
visionos affected apple
Upstream advisory

CVE-2026-64723

macOSCoalition ESS < 30%MEDIUM2026-07-27

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access sensitive user data.

CVEs:CVE-2026-64723

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64758

visionOSCoalition ESS < 30%HIGH2026-07-27

The issue was addressed with improved bounds checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination.

CVEs:CVE-2026-64758

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-43763

macOSCoalition ESS < 30%MEDIUM2026-07-27

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to read files outside of its sandbox.

CVEs:CVE-2026-43763

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43819

macOSCoalition ESS < 30%MEDIUM2026-07-27

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.6. An app may be able to access sensitive user data.

CVEs:CVE-2026-43819

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64776

macOSCoalition ESS < 30%MEDIUM2026-07-27

The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to disclose kernel memory.

CVEs:CVE-2026-64776

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64711

iPadOSCoalition ESS < 30%MEDIUM2026-07-27

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to leak sensitive user information.

CVEs:CVE-2026-64711

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2026-43747

macOSCoalition ESS < 30%HIGH2026-07-27

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Parsing a maliciously crafted file may lead to an unexpected app termination.

CVEs:CVE-2026-43747

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43782

macOSCoalition ESS < 30%MEDIUM2026-07-27

This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access sensitive user data.

CVEs:CVE-2026-43782

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-20672

macOSCoalition ESS < 30%HIGH2026-07-27

An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to access sensitive user data.

CVEs:CVE-2026-20672

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43775

macOSCoalition ESS < 30%MEDIUM2026-07-27

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. An app may be able to access sensitive user data.

CVEs:CVE-2026-43775

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64755

iPadOSCoalition ESS < 30%MEDIUM2026-07-27

An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6. An app may be able to access sensitive user data.

CVEs:CVE-2026-64755

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2026-64707

visionOSCoalition ESS < 30%MEDIUM2026-07-27

A permissions issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, visionOS 26.6. An app may be able to delete files for which it does not have permi...

CVEs:CVE-2026-64707

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
visionos affected apple
Upstream advisory

CVE-2026-43767

macOSCoalition ESS < 30%MEDIUM2026-07-27

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-43767

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64754

visionOSCoalition ESS < 30%CRITICAL2026-07-27

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously cra...

CVEs:CVE-2026-64754

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-43672

macOSCoalition ESS < 30%HIGH2026-07-27

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious application may be able to bypass Privacy preferences.

CVEs:CVE-2026-43672

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64737

macOSCoalition ESS < 30%HIGH2026-07-27

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox.

CVEs:CVE-2026-64737

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43756

macOSCoalition ESS < 30%HIGH2026-07-27

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access user-sensitive data.

CVEs:CVE-2026-43756

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-39874

macOSCoalition ESS < 30%CRITICAL2026-07-27

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.

CVEs:CVE-2026-39874

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43806

macOSCoalition ESS < 30%MEDIUM2026-07-27

A denial of service issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26.6. A local attacker may be able to cause a denial of service.

CVEs:CVE-2026-43806

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-64718

visionOSCoalition ESS < 30%CRITICAL2026-07-27

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unex...

CVEs:CVE-2026-64718

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2026-28900

macOSCoalition ESS < 30%MEDIUM2026-07-27

A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A maliciously crafted ZIP archive may bypass Gatekeeper checks.

CVEs:CVE-2026-28900

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-28849

macOSCoalition ESS < 30%MEDIUM2026-07-27

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A maliciously crafted ZIP archive may bypass Gatekeeper checks.

CVEs:CVE-2026-28849

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43665

macOSCoalition ESS < 30%MEDIUM2026-07-27

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A local attacker may be able to determine the legacy VNC password configured for Screen Sharing.

CVEs:CVE-2026-43665

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43693

macOSCoalition ESS < 30%CRITICAL2026-07-27

A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.

CVEs:CVE-2026-43693

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43781

macOSCoalition ESS < 30%MEDIUM2026-07-27

A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access sensitive user data.

CVEs:CVE-2026-43781

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43770

tvOSCoalition ESS < 30%MEDIUM2026-07-27

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6. An app may be able to access sensitive user data.

CVEs:CVE-2026-43770

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
tvos affected apple
Upstream advisory

CVE-2026-28926

macOSCoalition ESS < 30%HIGH2026-07-27

A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to elevate privileges.

CVEs:CVE-2026-28926

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43755

macOSCoalition ESS < 30%CRITICAL2026-07-27

A race condition was addressed with improved state management. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.

CVEs:CVE-2026-43755

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2026-43811

iPadOSCoalition ESS < 30%MEDIUM2026-07-27

A race condition was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6. An app may be able to modify protected parts of the file system.

CVEs:CVE-2026-43811

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2026-43820

OtherCoalition ESS < 30%HIGH2026-07-23

NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1_STRING, but not all SANs are backed by ASN1_STRING, so accessing the buffer for such a typ...

CVEs:CVE-2026-43820

Affected products

ProductStatusVendorPackageEcosystem
swift-nio-ssl affected Apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.