Apple Security Advisories · August 2026 — Apple Security Advisories
44 advisories 44 CVEs 1 EXPLOITED

Apple-vendor CVEs for 2026-08. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2026-65400

macOSExploitedCISA KEV listedCRITICAL2026-08-06

An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate t...

CVEs:CVE-2026-65400

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-65343

visionOSPoC exploitCRITICAL2026-08-17

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. A remote attacker may be able to cause unexpected system termination.

CVEs:CVE-2026-65343

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-65351

visionOSPoC exploitHIGH2026-08-17

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an u...

CVEs:CVE-2026-65351

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
safari affected apple — —
Upstream advisory

CVE-2026-65330

visionOSPoC exploitMEDIUM2026-08-17

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt k...

CVEs:CVE-2026-65330

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-64788

visionOSPoC exploitCRITICAL2026-08-17

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption.

CVEs:CVE-2026-64788

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-64705

iPadOSPoC exploitCRITICAL2026-08-25

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or write kernel memory.

CVEs:CVE-2026-64705

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-65349

visionOSPoC exploitMEDIUM2026-08-17

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination...

CVEs:CVE-2026-65349

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-65346

visionOSCoalition ESS < 30%CRITICAL2026-08-17

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing an image may lead to arbitrary code execution.

CVEs:CVE-2026-65346

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-64780

visionOSCoalition ESS < 30%HIGH2026-08-17

The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safa...

CVEs:CVE-2026-64780

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-43798

OtherCoalition ESS < 30%CRITICAL2026-08-20

A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write of attacker-controlled length and content against any application built on swift-nio-ssh. This vulnerability is addressed in swift-nio-ssh version 0.14.1.

CVEs:CVE-2026-43798

Affected products

ProductStatusVendorPackageEcosystem
swiftnio_ssh affected apple — —
Upstream advisory

CVE-2026-65331

visionOSCoalition ESS < 30%HIGH2026-08-17

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an u...

CVEs:CVE-2026-65331

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
safari affected apple — —
Upstream advisory

CVE-2026-43795

visionOSCoalition ESS < 30%HIGH2026-08-17

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpe...

CVEs:CVE-2026-43795

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
safari affected apple — —
Upstream advisory

CVE-2026-65340

visionOSCoalition ESS < 30%HIGH2026-08-17

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an u...

CVEs:CVE-2026-65340

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
safari affected apple — —
Upstream advisory

CVE-2026-65337

visionOSCoalition ESS < 30%HIGH2026-08-17

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an u...

CVEs:CVE-2026-65337

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
safari affected apple — —
Upstream advisory

CVE-2026-65336

visionOSCoalition ESS < 30%HIGH2026-08-17

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an u...

CVEs:CVE-2026-65336

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-64784

visionOSCoalition ESS < 30%HIGH2026-08-17

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content m...

CVEs:CVE-2026-64784

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
safari affected apple — —
Upstream advisory

CVE-2026-65335

visionOSCoalition ESS < 30%HIGH2026-08-17

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an u...

CVEs:CVE-2026-65335

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-65334

visionOSCoalition ESS < 30%CRITICAL2026-08-17

A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may ...

CVEs:CVE-2026-65334

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
safari affected apple — —
Upstream advisory

CVE-2026-65338

visionOSCoalition ESS < 30%HIGH2026-08-17

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpe...

CVEs:CVE-2026-65338

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
safari affected apple — —
Upstream advisory

CVE-2026-65332

visionOSCoalition ESS < 30%HIGH2026-08-17

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an u...

CVEs:CVE-2026-65332

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
safari affected apple — —
Upstream advisory

CVE-2026-64773

OtherCoalition ESS < 30%CRITICAL2026-08-20

An attacker that can reach a container's published TCP port may be able to force the host's forwarding process to buffer an unbounded amount of that client's data in memory, for as long as the backend container connection takes to complete — with no ...

CVEs:CVE-2026-64773

Affected products

ProductStatusVendorPackageEcosystem
container affected apple — —
Upstream advisory

CVE-2026-43794

visionOSCoalition ESS < 30%CRITICAL2026-08-17

A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously craf...

CVEs:CVE-2026-43794

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
safari affected apple — —
Upstream advisory

CVE-2026-65347

visionOSCoalition ESS < 30%HIGH2026-08-17

The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing an image may lead to a denial-of-service.

CVEs:CVE-2026-65347

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-43667

visionOSCoalition ESS < 30%MEDIUM2026-08-17

A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5, watchOS 26.5. An attacker in a privileged network position may be able...

CVEs:CVE-2026-43667

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2026-64715

visionOSCoalition ESS < 30%CRITICAL2026-08-17

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously craft...

CVEs:CVE-2026-64715

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
safari affected apple — —
Upstream advisory

CVE-2026-43670

iPadOSCoalition ESS < 30%CRITICAL2026-08-25

A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content ...

CVEs:CVE-2026-43670

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
safari affected apple — —
Upstream advisory

CVE-2026-64779

visionOSCoalition ESS < 30%CRITICAL2026-08-17

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may l...

CVEs:CVE-2026-64779

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-43678

OtherCoalition ESS < 30%MEDIUM2026-08-20

An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent after a completed WebSocket handshake, dropping all active connections until the process restarts. This vulnerabil...

CVEs:CVE-2026-43678

Affected products

ProductStatusVendorPackageEcosystem
swiftnio affected apple — —
Upstream advisory

CVE-2026-20679

macOSCoalition ESS < 30%MEDIUM2026-08-21

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. Processing a maliciously crafted file may lead to unexpected app termination.

CVEs:CVE-2026-20679

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-65370

OtherCoalition ESS < 30%HIGH2026-08-12

ServiceTalk HTTP/1.x incorrectly handles malformed Transfer-Encoding which could result in request smuggling attacks. This vulnerability is addressed in servicetalk version 0.42.65.

CVEs:CVE-2026-65370

Affected products

ProductStatusVendorPackageEcosystem
servicetalk affected apple — —
Upstream advisory

CVE-2026-64778

visionOSCoalition ESS < 30%HIGH2026-08-17

The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Visiting a maliciously crafted website may leak sens...

CVEs:CVE-2026-64778

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
safari affected apple — —
Upstream advisory

CVE-2026-64777

OtherCoalition ESS < 30%MEDIUM2026-08-20

A malicious builder peer may be able to request an in-context file by name from the host and receive the contents of whatever the name resolves to, even when it resolves outside the build context. This vulnerability is addressed in container version 1....

CVEs:CVE-2026-64777

Affected products

ProductStatusVendorPackageEcosystem
container affected apple — —
Upstream advisory

CVE-2026-64782

visionOSCoalition ESS < 30%CRITICAL2026-08-17

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may l...

CVEs:CVE-2026-64782

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
safari affected apple — —
Upstream advisory

CVE-2026-64787

visionOSCoalition ESS < 30%CRITICAL2026-08-17

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously craft...

CVEs:CVE-2026-64787

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
safari affected apple — —
Upstream advisory

CVE-2026-65333

visionOSCoalition ESS < 30%HIGH2026-08-17

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an u...

CVEs:CVE-2026-65333

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-64781

visionOSCoalition ESS < 30%HIGH2026-08-17

The issue was addressed with improved input validation. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexp...

CVEs:CVE-2026-64781

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-65341

visionOSCoalition ESS < 30%CRITICAL2026-08-17

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content ...

CVEs:CVE-2026-65341

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
safari affected apple — —
Upstream advisory

CVE-2026-65329

iPadOSCoalition ESS < 30%HIGH2026-08-17

An authentication issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, iOS 27 and iPadOS 27. An attacker in a privileged network position may be able to bypass IPSec authentication and intercept netwo...

CVEs:CVE-2026-65329

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2026-28984

visionOSCoalition ESS < 30%HIGH2026-08-17

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content ma...

CVEs:CVE-2026-28984

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2026-43679

watchOSCoalition ESS < 30%LOW2026-08-21

This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An attacker with physical access to a locked Apple Watch may be able to view user contacts.

CVEs:CVE-2026-43679

Affected products

ProductStatusVendorPackageEcosystem
watchos affected apple — —
Upstream advisory

CVE-2026-64760

visionOSCoalition ESS < 30%HIGH2026-08-17

An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to leak sensitive kernel state.

CVEs:CVE-2026-64760

Affected products

ProductStatusVendorPackageEcosystem
iOS and iPadOS affected Apple — —
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2026-65339

visionOSCoalition ESS < 30%MEDIUM2026-08-17

A logic issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to leak sensitive user information.

CVEs:CVE-2026-65339

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-65367

iPadOSCoalition ESS < 30%MEDIUM2026-08-25

A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-65367

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2026-43657

iPadOSCoalition ESS < 30%LOW2026-08-25

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and iPadOS 26.5. A malicious app may be able to enumerate installed apps.

CVEs:CVE-2026-43657

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple — —
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.