Apple Security Advisories · September 2026 — Apple Security Advisories
246 advisories 246 CVEs 1 EXPLOITED

Apple-vendor CVEs for 2026-09. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2026-86950

iPadOSExploitedCISA KEV listedCRITICAL2026-09-28

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple i...

CVEs:CVE-2026-86950

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-65374

macOSPoC exploitCRITICAL2026-09-14

A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious WebDAV server may result in code execution.

CVEs:CVE-2026-65374

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
macOS affected Apple — —
Upstream advisory

CVE-2026-43687

visionOSPoC exploitMEDIUM2026-09-14

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Connecting to a malicious NFS server may disclose ke...

CVEs:CVE-2026-43687

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84543

macOSPoC exploitHIGH2026-09-14

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB server may cause unexpected system termination or corrupt kernel...

CVEs:CVE-2026-84543

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84600

visionOSPoC exploitMEDIUM2026-09-14

An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. A malicious shortcut may be able to send messages without user confirmation.

CVEs:CVE-2026-84600

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84568

macOSPoC exploitCRITICAL2026-09-14

A path traversal issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker with control of a network directory server may be able to execute arbitrary code with roo...

CVEs:CVE-2026-84568

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-43786

macOSPoC exploitCRITICAL2026-09-14

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.

CVEs:CVE-2026-43786

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84616

visionOSPoC exploitMEDIUM2026-09-14

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able ...

CVEs:CVE-2026-84616

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-43783

macOSPoC exploitCRITICAL2026-09-14

A race condition was addressed with improved locking. This issue is fixed in macOS Tahoe 26.6. A malicious app may be able to gain root privileges.

CVEs:CVE-2026-43783

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84607

visionOSPoC exploitCRITICAL2026-09-14

A race condition was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A sandboxed app may be a...

CVEs:CVE-2026-84607

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-65414

visionOSCoalition ESS < 30%CRITICAL2026-09-14

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A remote atta...

CVEs:CVE-2026-65414

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-43790

macOSCoalition ESS < 30%CRITICAL2026-09-14

The issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.

CVEs:CVE-2026-43790

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84553

macOSCoalition ESS < 30%CRITICAL2026-09-14

A resource exhaustion issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A remote attacker may be able to cause a denial-of-service.

CVEs:CVE-2026-84553

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-65364

macOSCoalition ESS < 30%HIGH2026-09-14

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A remote attacker may be able to cause unexpected system termination.

CVEs:CVE-2026-65364

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-43692

macOSCoalition ESS < 30%CRITICAL2026-09-14

A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A remote user may cause an unexpected app termination or arbitrary code execution.

CVEs:CVE-2026-43692

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84561

visionOSCoalition ESS < 30%CRITICAL2026-09-14

A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able t...

CVEs:CVE-2026-84561

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84609

visionOSCoalition ESS < 30%CRITICAL2026-09-14

A permissions issue was addressed with improved path validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to modify protected system fi...

CVEs:CVE-2026-84609

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-65375

macOSCoalition ESS < 30%HIGH2026-09-14

The issue was addressed with improved authentication. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-65375

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84549

macOSCoalition ESS < 30%HIGH2026-09-14

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious NFS server may cause unexpected system termination or corrupt kernel memory.

CVEs:CVE-2026-84549

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
macOS affected Apple — —
Upstream advisory

CVE-2026-84544

macOSCoalition ESS < 30%CRITICAL2026-09-14

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious NFS server may cause unexpected system termination or corrupt kernel memory.

CVEs:CVE-2026-84544

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
macOS affected Apple — —
Upstream advisory

CVE-2026-28960

iPadOSCoalition ESS < 30%HIGH2026-09-14

A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. A remote attacker may be able to cause a denial-of-service.

CVEs:CVE-2026-28960

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2026-43686

visionOSCoalition ESS < 30%CRITICAL2026-09-14

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Connecting to a m...

CVEs:CVE-2026-43686

Affected products

ProductStatusVendorPackageEcosystem
iOS and iPadOS affected Apple — —
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-65410

visionOSCoalition ESS < 30%HIGH2026-09-14

The issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-65410

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84598

iPadOSCoalition ESS < 30%HIGH2026-09-14

A path traversal issue was addressed with improved path validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27. An attacker with physical access to a trust-paired device may be able to read and write arbitrary files.

CVEs:CVE-2026-84598

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2026-84538

macOSCoalition ESS < 30%HIGH2026-09-14

A denial-of-service issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A remote attacker may be able to cause a denial-of-service.

CVEs:CVE-2026-84538

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84554

macOSCoalition ESS < 30%HIGH2026-09-14

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker in a privileged network position may be able to cause a denial-of-service.

CVEs:CVE-2026-84554

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-28935

visionOSCoalition ESS < 30%HIGH2026-09-14

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt k...

CVEs:CVE-2026-28935

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84512

macOSCoalition ESS < 30%CRITICAL2026-09-14

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory.

CVEs:CVE-2026-84512

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-43815

macOSCoalition ESS < 30%CRITICAL2026-09-14

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Connecting to a malicious afpfs server may lead to kernel memory corruption.

CVEs:CVE-2026-43815

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
macOS affected Apple — —
Upstream advisory

CVE-2026-84625

visionOSCoalition ESS < 30%CRITICAL2026-09-14

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27, watchOS 27. An app may be able to fingerprint the user.

CVEs:CVE-2026-84625

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-65412

visionOSCoalition ESS < 30%HIGH2026-09-14

A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, watchOS 27. Processing web content ...

CVEs:CVE-2026-65412

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-65395

visionOSCoalition ESS < 30%CRITICAL2026-09-14

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. Processing a maliciously ...

CVEs:CVE-2026-65395

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
Upstream advisory

CVE-2026-84487

visionOSCoalition ESS < 30%CRITICAL2026-09-14

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciou...

CVEs:CVE-2026-84487

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-43791

macOSCoalition ESS < 30%HIGH2026-09-14

A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to read arbitrary files.

CVEs:CVE-2026-43791

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84510

iPadOSCoalition ESS < 30%CRITICAL2026-09-14

A heap buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a maliciously crafted volume may lead to une...

CVEs:CVE-2026-84510

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-84520

macOSCoalition ESS < 30%CRITICAL2026-09-14

A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Golden Gate 27. A local attacker may be able to cause unexpected system termination or corrupt kernel memory.

CVEs:CVE-2026-84520

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-28934

macOSCoalition ESS < 30%CRITICAL2026-09-14

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a malicious disk image may cause unexpected system termination.

CVEs:CVE-2026-28934

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84563

macOSCoalition ESS < 30%HIGH2026-09-14

A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-84563

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84524

visionOSCoalition ESS < 30%MEDIUM2026-09-14

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a malicio...

CVEs:CVE-2026-84524

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84526

visionOSCoalition ESS < 30%CRITICAL2026-09-14

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a ...

CVEs:CVE-2026-84526

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84516

macOSCoalition ESS < 30%HIGH2026-09-14

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Processing a maliciously crafted file may result in unexpected app termination or disclosure of proces...

CVEs:CVE-2026-84516

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84629

visionOSCoalition ESS < 30%HIGH2026-09-14

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to fingerprint the user.

CVEs:CVE-2026-84629

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84519

iPadOSCoalition ESS < 30%CRITICAL2026-09-14

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a disk image with maliciously crafted ...

CVEs:CVE-2026-84519

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-28966

visionOSCoalition ESS < 30%CRITICAL2026-09-14

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. Processing a maliciously ...

CVEs:CVE-2026-28966

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
Upstream advisory

CVE-2026-65391

visionOSCoalition ESS < 30%CRITICAL2026-09-14

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to m...

CVEs:CVE-2026-65391

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
safari affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-65390

visionOSCoalition ESS < 30%CRITICAL2026-09-14

An integer overflow was addressed with improved input validation. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory co...

CVEs:CVE-2026-65390

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
safari affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84596

visionOSCoalition ESS < 30%MEDIUM2026-09-14

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted font may result in the disclosure of process memory.

CVEs:CVE-2026-84596

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84597

visionOSCoalition ESS < 30%MEDIUM2026-09-14

An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted font may result in the disclosure of process...

CVEs:CVE-2026-84597

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84606

visionOSCoalition ESS < 30%HIGH2026-09-14

A privacy issue was addressed with improved handling of identifiers. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. An app may be able to identify a user across reinstalls.

CVEs:CVE-2026-84606

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
visionos affected apple — —
Upstream advisory

CVE-2026-43761

macOSCoalition ESS < 30%CRITICAL2026-09-14

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Mounting a malicious disk image may cause unexpected system termination.

CVEs:CVE-2026-43761

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84509

macOSCoalition ESS < 30%MEDIUM2026-09-14

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB server may lead to unexpected system termination.

CVEs:CVE-2026-84509

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-43677

macOSCoalition ESS < 30%CRITICAL2026-09-14

An out-of-bounds write issue was addressed by removing the vulnerable code. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious WebDAV server may lead to unexpected app termination.

CVEs:CVE-2026-43677

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84536

macOSCoalition ESS < 30%MEDIUM2026-09-14

An integer underflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB server may lead to unexpected system termination.

CVEs:CVE-2026-84536

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84571

visionOSCoalition ESS < 30%CRITICAL2026-09-14

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted image may lead to unexpected app termination.

CVEs:CVE-2026-84571

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-43787

macOSCoalition ESS < 30%MEDIUM2026-09-14

A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker in a privileged network position may be able to leak sensitive user information.

CVEs:CVE-2026-43787

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-43719

macOSCoalition ESS < 30%CRITICAL2026-09-14

A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a maliciously crafted SMB network share may lead to system termination.

CVEs:CVE-2026-43719

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-65365

macOSCoalition ESS < 30%MEDIUM2026-09-14

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB share may disclose kernel memory.

CVEs:CVE-2026-65365

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84564

visionOSCoalition ESS < 30%MEDIUM2026-09-14

An uninitialized memory issue was addressed with improved memory initialization. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Proces...

CVEs:CVE-2026-84564

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-28938

iPadOSCoalition ESS < 30%HIGH2026-09-14

A privacy issue was addressed by moving sensitive data. This issue is fixed in iOS 26.6 and iPadOS 26.6. An app may be able to fingerprint the user.

CVEs:CVE-2026-28938

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2026-84635

visionOSCoalition ESS < 30%MEDIUM2026-09-14

A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to an unexpected process ter...

CVEs:CVE-2026-84635

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
safari affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84532

visionOSCoalition ESS < 30%MEDIUM2026-09-14

An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. Opening a maliciously cra...

CVEs:CVE-2026-84532

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
Upstream advisory

CVE-2026-65381

macOSCoalition ESS < 30%CRITICAL2026-09-14

A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A malicious app may be able to ...

CVEs:CVE-2026-65381

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-64761

iPadOSCoalition ESS < 30%HIGH2026-09-14

A privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS 27 and iPadOS 27. An app may be able to identify what other apps a user has installed.

CVEs:CVE-2026-64761

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2026-65355

visionOSCoalition ESS < 30%HIGH2026-09-14

An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 26.6.1. A website may be able to determine a user's IP addre...

CVEs:CVE-2026-65355

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
visionos affected apple — —
Upstream advisory

CVE-2026-84623

iPadOSCoalition ESS < 30%HIGH2026-09-14

An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27. An app may be able to fingerprint the device.

CVEs:CVE-2026-84623

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2026-84588

macOSCoalition ESS < 30%CRITICAL2026-09-14

A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in macOS Golden Gate 27. Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory.

CVEs:CVE-2026-84588

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84518

iPadOSCoalition ESS < 30%MEDIUM2026-09-14

This issue was addressed through improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27. A malicious website may be able to determine what apps a user has installed.

CVEs:CVE-2026-84518

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
safari affected apple — —
Upstream advisory

CVE-2026-65352

visionOSCoalition ESS < 30%HIGH2026-09-14

An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 26.6.1. A website may be able to determine a user's IP address with Private Relay turned on.

CVEs:CVE-2026-65352

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
visionos affected apple — —
Upstream advisory

CVE-2026-65415

visionOSCoalition ESS < 30%HIGH2026-09-14

A race condition was addressed with additional validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. A local user may be able to cause unexpected system termination or read kernel memory.

CVEs:CVE-2026-65415

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-43697

macOSCoalition ESS < 30%HIGH2026-09-14

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Processing a maliciously crafted 3D file may lead to an out-of-bounds read.

CVEs:CVE-2026-43697

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-43789

macOSCoalition ESS < 30%HIGH2026-09-14

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access user-sensitive data.

CVEs:CVE-2026-43789

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-65342

macOSCoalition ESS < 30%HIGH2026-09-14

A permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.

CVEs:CVE-2026-65342

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-65378

macOSCoalition ESS < 30%HIGH2026-09-14

An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.

CVEs:CVE-2026-65378

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-64753

visionOSCoalition ESS < 30%MEDIUM2026-09-14

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may disclose sensitive user in...

CVEs:CVE-2026-64753

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
safari affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-43696

macOSCoalition ESS < 30%MEDIUM2026-09-14

An authorization issue was addressed with improved entitlement checks. This issue is fixed in macOS Golden Gate 27. An app may be able to capture Touch Bar content without authorization.

CVEs:CVE-2026-43696

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84522

macOSCoalition ESS < 30%MEDIUM2026-09-14

A race condition was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to access sensitive user data.

CVEs:CVE-2026-84522

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-43674

iPadOSCoalition ESS < 30%MEDIUM2026-09-14

An authentication issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27. An attacker with physical access to an unlocked device may be able to view Wi-Fi passwords without authentication.

CVEs:CVE-2026-43674

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2026-84581

macOSCoalition ESS < 30%CRITICAL2026-09-14

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory.

CVEs:CVE-2026-84581

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-28836

macOSCoalition ESS < 30%MEDIUM2026-09-14

A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8.8. An attacker with physical access may be able to silently persist an Apple Account on an erased device.

CVEs:CVE-2026-28836

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-64790

macOSCoalition ESS < 30%HIGH2026-09-14

A path handling issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain elevated privileges.

CVEs:CVE-2026-64790

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84584

macOSCoalition ESS < 30%HIGH2026-09-14

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Golden Gate 27. An app may be able to break out of its sandbox.

CVEs:CVE-2026-84584

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84546

visionOSCoalition ESS < 30%CRITICAL2026-09-14

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a ...

CVEs:CVE-2026-84546

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-43691

macOSCoalition ESS < 30%CRITICAL2026-09-14

A path handling issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.

CVEs:CVE-2026-43691

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-20683

visionOSCoalition ESS < 30%HIGH2026-09-14

An authentication issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27. An app may be able to use the Sign In With Apple authentication ...

CVEs:CVE-2026-20683

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
visionos affected apple — —
Upstream advisory

CVE-2026-84497

visionOSCoalition ESS < 30%CRITICAL2026-09-14

A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. Opening a maliciously crafted file m...

CVEs:CVE-2026-84497

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
Upstream advisory

CVE-2026-84541

macOSCoalition ESS < 30%MEDIUM2026-09-14

An input validation issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An application may be able to access restricted files.

CVEs:CVE-2026-84541

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84534

visionOSCoalition ESS < 30%HIGH2026-09-14

A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27. Extracting a maliciously crafted archive may a...

CVEs:CVE-2026-84534

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
visionos affected apple — —
Upstream advisory

CVE-2026-64756

iPadOSCoalition ESS < 30%HIGH2026-09-14

A path handling issue was addressed with improved validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access user-sensitive data.

CVEs:CVE-2026-64756

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-84624

visionOSCoalition ESS < 30%MEDIUM2026-09-14

A permissions issue was addressed with improved path validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27. A sandboxed app may be able to access restr...

CVEs:CVE-2026-84624

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
visionos affected apple — —
Upstream advisory

CVE-2026-84622

visionOSCoalition ESS < 30%MEDIUM2026-09-14

A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app with ...

CVEs:CVE-2026-84622

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-65382

macOSCoalition ESS < 30%MEDIUM2026-09-14

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.

CVEs:CVE-2026-65382

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-65380

macOSCoalition ESS < 30%MEDIUM2026-09-14

An issue existed in the handling of snapshots. The issue was resolved with improved permissions logic. This issue is fixed in macOS Golden Gate 27. An app may be able to access protected user data.

CVEs:CVE-2026-65380

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84578

macOSCoalition ESS < 30%HIGH2026-09-14

A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to break out of its sandbox.

CVEs:CVE-2026-84578

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84515

macOSCoalition ESS < 30%CRITICAL2026-09-14

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB server may lead to kernel memory corruption.

CVEs:CVE-2026-84515

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
macOS affected Apple — —
Upstream advisory

CVE-2026-84505

macOSCoalition ESS < 30%CRITICAL2026-09-14

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.

CVEs:CVE-2026-84505

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84506

macOSCoalition ESS < 30%CRITICAL2026-09-14

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2026-84506

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-43702

iPadOSCoalition ESS < 30%HIGH2026-09-14

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, iOS 26.7 and iPadOS 26.7, macOS Sequoia 15.8, macOS Tahoe 26.6, macOS Tahoe 26.7, tvOS 26.6, watchOS 26.6. Processing a maliciously crafted video fi...

CVEs:CVE-2026-43702

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-65344

visionOSCoalition ESS < 30%CRITICAL2026-09-14

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. Processing a maliciously ...

CVEs:CVE-2026-65344

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
Upstream advisory

CVE-2026-64752

visionOSCoalition ESS < 30%CRITICAL2026-09-14

A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. Processing a maliciously crafted image may lead to arbitrary code execution.

CVEs:CVE-2026-64752

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
visionos affected apple — —
Upstream advisory

CVE-2026-65411

visionOSCoalition ESS < 30%MEDIUM2026-09-14

A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS 27. An app may be able to modify protected parts of the file system.

CVEs:CVE-2026-65411

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
visionos affected apple — —
Upstream advisory

CVE-2026-65407

iPadOSCoalition ESS < 30%CRITICAL2026-09-14

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.6, macOS Tahoe 26.7, tvOS 26...

CVEs:CVE-2026-65407

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84575

visionOSCoalition ESS < 30%CRITICAL2026-09-14

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted file m...

CVEs:CVE-2026-84575

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84489

iPadOSCoalition ESS < 30%CRITICAL2026-09-14

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to cause a denial of service.

CVEs:CVE-2026-84489

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-65357

visionOSCoalition ESS < 30%HIGH2026-09-14

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.

CVEs:CVE-2026-65357

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84548

macOSCoalition ESS < 30%CRITICAL2026-09-14

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Processing a maliciously crafted document may lead to an out-of-bounds read.

CVEs:CVE-2026-84548

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84577

macOSCoalition ESS < 30%HIGH2026-09-14

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Golden Gate 27, macOS Tahoe 26.7. An app may be able to bypass sandbox restrictions.

CVEs:CVE-2026-84577

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84566

iPadOSCoalition ESS < 30%HIGH2026-09-14

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A local attacker may be able to cause unexpected system terminatio...

CVEs:CVE-2026-84566

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-43684

iPadOSCoalition ESS < 30%CRITICAL2026-09-14

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, macOS Golden Gate 27, macOS Sequoia 15.8. An app may be able to cause unexpected system termination or corrupt kernel memory.

CVEs:CVE-2026-43684

Affected products

ProductStatusVendorPackageEcosystem
iOS and iPadOS affected Apple — —
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-65369

macOSCoalition ESS < 30%MEDIUM2026-09-14

A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A malicious application may bypass Gatekeeper checks.

CVEs:CVE-2026-65369

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84611

visionOSCoalition ESS < 30%CRITICAL2026-09-14

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a ...

CVEs:CVE-2026-84611

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84565

macOSCoalition ESS < 30%HIGH2026-09-14

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Processing a maliciously crafted disk image may lead to unexpected app termination.

CVEs:CVE-2026-84565

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84620

visionOSCoalition ESS < 30%CRITICAL2026-09-14

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciou...

CVEs:CVE-2026-84620

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84511

visionOSCoalition ESS < 30%CRITICAL2026-09-14

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted asset ...

CVEs:CVE-2026-84511

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84632

visionOSCoalition ESS < 30%CRITICAL2026-09-14

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted...

CVEs:CVE-2026-84632

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-65413

macOSCoalition ESS < 30%CRITICAL2026-09-14

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause a denial of service.

CVEs:CVE-2026-65413

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84533

iPadOSCoalition ESS < 30%MEDIUM2026-09-14

A cryptographic issue was addressed with improved integrity checks. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27. An attacker in a privileged network position may be able to modify network traffic.

CVEs:CVE-2026-84533

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-65398

visionOSCoalition ESS < 30%HIGH2026-09-14

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel ...

CVEs:CVE-2026-65398

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-65405

visionOSCoalition ESS < 30%MEDIUM2026-09-14

A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may b...

CVEs:CVE-2026-65405

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-43664

iPadOSCoalition ESS < 30%MEDIUM2026-09-14

This issue was addressed with improved data protection. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, watchOS 27. An app may be able to access sensitive user ...

CVEs:CVE-2026-43664

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84572

macOSCoalition ESS < 30%HIGH2026-09-14

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination or read kernel memory.

CVEs:CVE-2026-84572

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-28899

macOSCoalition ESS < 30%MEDIUM2026-09-14

A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.6, macOS Tahoe 26.7. An app may bypass Gatekeeper checks.

CVEs:CVE-2026-28899

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-43683

macOSCoalition ESS < 30%HIGH2026-09-14

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected process termination or disclose process memory.

CVEs:CVE-2026-43683

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-43688

iPadOSCoalition ESS < 30%CRITICAL2026-09-14

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27. Processing a maliciously crafted file may lead to unexpected app termination.

CVEs:CVE-2026-43688

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-65406

visionOSCoalition ESS < 30%MEDIUM2026-09-14

A logic issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. An app may be able to access sensitive user d...

CVEs:CVE-2026-65406

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
Upstream advisory

CVE-2026-84583

visionOSCoalition ESS < 30%MEDIUM2026-09-14

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A local app may be able...

CVEs:CVE-2026-84583

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-64736

visionOSCoalition ESS < 30%HIGH2026-09-14

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system term...

CVEs:CVE-2026-64736

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84535

macOSCoalition ESS < 30%HIGH2026-09-14

An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to break out of its sandbox.

CVEs:CVE-2026-84535

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-65409

visionOSCoalition ESS < 30%HIGH2026-09-14

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able ...

CVEs:CVE-2026-65409

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84559

macOSCoalition ESS < 30%MEDIUM2026-09-14

A permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A malicious application may be able to access restricted files.

CVEs:CVE-2026-84559

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-64714

iPadOSCoalition ESS < 30%CRITICAL2026-09-14

A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. Processing a maliciously crafted image may lead to a denial-o...

CVEs:CVE-2026-64714

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
visionos affected apple — —
Upstream advisory

CVE-2026-84576

macOSCoalition ESS < 30%MEDIUM2026-09-14

This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.

CVEs:CVE-2026-84576

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-65376

macOSCoalition ESS < 30%MEDIUM2026-09-14

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-65376

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84513

visionOSCoalition ESS < 30%MEDIUM2026-09-14

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A m...

CVEs:CVE-2026-84513

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84619

macOSCoalition ESS < 30%CRITICAL2026-09-14

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination or write kernel memory.

CVEs:CVE-2026-84619

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84567

macOSCoalition ESS < 30%MEDIUM2026-09-14

The issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-84567

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84517

macOSCoalition ESS < 30%CRITICAL2026-09-14

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-84517

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84523

visionOSCoalition ESS < 30%CRITICAL2026-09-14

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be...

CVEs:CVE-2026-84523

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-65408

iPadOSCoalition ESS < 30%CRITICAL2026-09-14

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-65408

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-65377

visionOSCoalition ESS < 30%CRITICAL2026-09-14

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be ab...

CVEs:CVE-2026-65377

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84552

iPadOSCoalition ESS < 30%MEDIUM2026-09-14

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-84552

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-28968

visionOSCoalition ESS < 30%CRITICAL2026-09-14

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be...

CVEs:CVE-2026-28968

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84602

visionOSCoalition ESS < 30%MEDIUM2026-09-14

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause ...

CVEs:CVE-2026-84602

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84537

macOSCoalition ESS < 30%MEDIUM2026-09-14

The issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination or corrupt kernel memory.

CVEs:CVE-2026-84537

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-43741

macOSCoalition ESS < 30%MEDIUM2026-09-14

A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access protected user data.

CVEs:CVE-2026-43741

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-28937

macOSCoalition ESS < 30%MEDIUM2026-09-14

This issue was addressed through improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to access sensitive user data.

CVEs:CVE-2026-28937

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-65393

macOSCoalition ESS < 30%HIGH2026-09-14

A permissions issue was addressed with improved validation. This issue is fixed in Xcode 27, macOS Golden Gate 27. An app may be able to access user-sensitive data.

CVEs:CVE-2026-65393

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
xcode affected apple — —
Upstream advisory

CVE-2026-84618

macOSCoalition ESS < 30%MEDIUM2026-09-14

A permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.

CVEs:CVE-2026-84618

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84527

visionOSCoalition ESS < 30%MEDIUM2026-09-14

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to access sensitive user data.

CVEs:CVE-2026-84527

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84585

macOSCoalition ESS < 30%MEDIUM2026-09-14

A permissions issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to access local network devices without user consent.

CVEs:CVE-2026-84585

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-43762

visionOSCoalition ESS < 30%HIGH2026-09-14

The issue was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6. An app may be able to access user-sensitive data.

CVEs:CVE-2026-43762

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
visionos affected apple — —
Upstream advisory

CVE-2026-84586

watchOSCoalition ESS < 30%HIGH2026-09-14

An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, watchOS 27. A malicious application may be able to leak sensitive user information.

CVEs:CVE-2026-84586

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84570

macOSCoalition ESS < 30%MEDIUM2026-09-14

A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to bypass Gatekeeper checks.

CVEs:CVE-2026-84570

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84555

macOSCoalition ESS < 30%MEDIUM2026-09-14

An authorization issue was addressed with improved access control. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8. An app may be able to access sensitive user data.

CVEs:CVE-2026-84555

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-43737

iPadOSCoalition ESS < 30%MEDIUM2026-09-14

An authorization issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, watchOS 27. An app may be able to access motion d...

CVEs:CVE-2026-43737

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-28933

macOSCoalition ESS < 30%CRITICAL2026-09-14

A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-28933

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-65348

iPadOSCoalition ESS < 30%MEDIUM2026-09-14

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to modify protected parts of the file ...

CVEs:CVE-2026-65348

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-84628

visionOSCoalition ESS < 30%MEDIUM2026-09-14

An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. A sandboxed app may be able to access the System Keychain.

CVEs:CVE-2026-84628

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-65345

iPadOSCoalition ESS < 30%HIGH2026-09-14

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access user-sensitive data.

CVEs:CVE-2026-65345

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-84612

visionOSCoalition ESS < 30%MEDIUM2026-09-14

An authorization issue was addressed with improved access control. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able t...

CVEs:CVE-2026-84612

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-65371

visionOSCoalition ESS < 30%HIGH2026-09-14

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to disclose kernel memory.

CVEs:CVE-2026-65371

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84626

visionOSCoalition ESS < 30%HIGH2026-09-14

An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app ma...

CVEs:CVE-2026-84626

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-65402

visionOSCoalition ESS < 30%CRITICAL2026-09-14

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be abl...

CVEs:CVE-2026-65402

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-65362

macOSCoalition ESS < 30%CRITICAL2026-09-14

This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.

CVEs:CVE-2026-65362

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-65359

visionOSCoalition ESS < 30%HIGH2026-09-14

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A local user may be ...

CVEs:CVE-2026-65359

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-64712

macOSCoalition ESS < 30%CRITICAL2026-09-14

This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.

CVEs:CVE-2026-64712

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84521

visionOSCoalition ESS < 30%CRITICAL2026-09-14

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27. An app may be able to cause unexpected...

CVEs:CVE-2026-84521

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
visionos affected apple — —
Upstream advisory

CVE-2026-43808

iPadOSCoalition ESS < 30%CRITICAL2026-09-14

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-43808

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84558

macOSCoalition ESS < 30%CRITICAL2026-09-14

A double free issue was addressed with improved memory management. This issue is fixed in macOS Golden Gate 27. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-84558

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84593

iPadOSCoalition ESS < 30%CRITICAL2026-09-14

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 27 and iPadOS 27. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-84593

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2026-43689

visionOSCoalition ESS < 30%CRITICAL2026-09-14

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. A malicious app may be able to gain root privileges.

CVEs:CVE-2026-43689

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
visionos affected apple — —
Upstream advisory

CVE-2026-84580

macOSCoalition ESS < 30%HIGH2026-09-14

The issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to break out of its sandbox.

CVEs:CVE-2026-84580

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84525

macOSCoalition ESS < 30%HIGH2026-09-14

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access user-sensitive data.

CVEs:CVE-2026-84525

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84631

macOSCoalition ESS < 30%CRITICAL2026-09-14

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27. An app may be able to gain root privileges.

CVEs:CVE-2026-84631

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-65404

iPadOSCoalition ESS < 30%MEDIUM2026-09-14

An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A malicious application may be able to by...

CVEs:CVE-2026-65404

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-84531

iPadOSCoalition ESS < 30%CRITICAL2026-09-14

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27. Processing maliciously crafted NTLM input may lead to unexpected app termination.

CVEs:CVE-2026-84531

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-43788

macOSCoalition ESS < 30%CRITICAL2026-09-14

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents.

CVEs:CVE-2026-43788

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84530

visionOSCoalition ESS < 30%HIGH2026-09-14

An information disclosure issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to disclo...

CVEs:CVE-2026-84530

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-64701

macOSCoalition ESS < 30%CRITICAL2026-09-14

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.

CVEs:CVE-2026-64701

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84573

macOSCoalition ESS < 30%MEDIUM2026-09-14

This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.

CVEs:CVE-2026-84573

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-65361

macOSCoalition ESS < 30%MEDIUM2026-09-14

This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.

CVEs:CVE-2026-65361

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84587

macOSCoalition ESS < 30%MEDIUM2026-09-14

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access protected user data.

CVEs:CVE-2026-84587

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84603

visionOSCoalition ESS < 30%MEDIUM2026-09-14

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, visionOS 27, watchOS 27. An app may be able to access sensitive user data.

CVEs:CVE-2026-84603

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84540

macOSCoalition ESS < 30%MEDIUM2026-09-14

An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.

CVEs:CVE-2026-84540

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84621

iPadOSCoalition ESS < 30%MEDIUM2026-09-14

An authorization issue was addressed with improved access control. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.

CVEs:CVE-2026-84621

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-43785

visionOSCoalition ESS < 30%MEDIUM2026-09-14

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. An app may be able to modify a file it only had permission to...

CVEs:CVE-2026-43785

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
Upstream advisory

CVE-2026-84615

visionOSCoalition ESS < 30%MEDIUM2026-09-14

An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, tvOS 27, visionOS 27. An app may be able to access sensitive user data.

CVEs:CVE-2026-84615

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
tvos affected apple — —
visionos affected apple — —
Upstream advisory

CVE-2026-84560

visionOSCoalition ESS < 30%MEDIUM2026-09-14

An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may gain unauthorized access to Bluetooth.

CVEs:CVE-2026-84560

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84574

macOSCoalition ESS < 30%MEDIUM2026-09-14

A permissions issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to bypass Privacy preferences.

CVEs:CVE-2026-84574

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84569

macOSCoalition ESS < 30%MEDIUM2026-09-14

An access issue was addressed with additional sandbox restrictions on the system pasteboards. This issue is fixed in macOS Golden Gate 27. An app may be able to access sensitive user data.

CVEs:CVE-2026-84569

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-65354

iPadOSCoalition ESS < 30%HIGH2026-09-14

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27. A malicious app may be able to break out of its sandbox.

CVEs:CVE-2026-65354

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-84556

macOSCoalition ESS < 30%MEDIUM2026-09-14

An authorization issue was addressed with improved access control. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.

CVEs:CVE-2026-84556

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-65353

iPadOSCoalition ESS < 30%MEDIUM2026-09-14

An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6. An app may be able to access sensitive user data.

CVEs:CVE-2026-65353

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-65403

visionOSCoalition ESS < 30%MEDIUM2026-09-14

This issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, watchOS 27. An app may be able to access sensitive user data.

CVEs:CVE-2026-65403

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84617

iPadOSCoalition ESS < 30%MEDIUM2026-09-14

An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27. An app may be able to access sensitive user...

CVEs:CVE-2026-84617

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2026-84636

visionOSCoalition ESS < 30%MEDIUM2026-09-14

An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to access sensitive user data.

CVEs:CVE-2026-84636

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84551

visionOSCoalition ESS < 30%MEDIUM2026-09-14

A logic issue was addressed with improved validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27, watchOS 27. An app may be able to bypass network restrictions.

CVEs:CVE-2026-84551

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-43695

visionOSCoalition ESS < 30%MEDIUM2026-09-14

An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to access sensitive user ...

CVEs:CVE-2026-43695

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84491

visionOSCoalition ESS < 30%MEDIUM2026-09-14

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to access sensitive user data.

CVEs:CVE-2026-84491

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84514

macOSCoalition ESS < 30%MEDIUM2026-09-14

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to modify protected parts of the file system.

CVEs:CVE-2026-84514

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84601

macOSCoalition ESS < 30%MEDIUM2026-09-14

A permissions issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to bypass Apple Intelligence security prompts.

CVEs:CVE-2026-84601

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-65399

visionOSCoalition ESS < 30%MEDIUM2026-09-14

A file quarantine bypass was addressed with additional checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, watchOS 27. An archive may be able to bypass ...

CVEs:CVE-2026-65399

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84589

macOSCoalition ESS < 30%MEDIUM2026-09-14

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27. An app may be able to modify Privacy preferences.

CVEs:CVE-2026-84589

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-65383

macOSCoalition ESS < 30%MEDIUM2026-09-14

This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27. An app may bypass Gatekeeper checks.

CVEs:CVE-2026-65383

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84507

visionOSCoalition ESS < 30%HIGH2026-09-14

A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to caus...

CVEs:CVE-2026-84507

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-64717

visionOSCoalition ESS < 30%MEDIUM2026-09-14

A race condition was addressed with improved state handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause un...

CVEs:CVE-2026-64717

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84550

macOSCoalition ESS < 30%MEDIUM2026-09-14

A race condition was addressed with additional validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-84550

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84492

visionOSCoalition ESS < 30%MEDIUM2026-09-14

A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to caus...

CVEs:CVE-2026-84492

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-65360

visionOSCoalition ESS < 30%MEDIUM2026-09-14

A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to caus...

CVEs:CVE-2026-65360

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-65401

macOSCoalition ESS < 30%MEDIUM2026-09-14

A race condition was addressed with improved state handling. This issue is fixed in macOS Golden Gate 27, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.

CVEs:CVE-2026-65401

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-65358

visionOSCoalition ESS < 30%MEDIUM2026-09-14

A race condition was addressed with improved state handling. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termin...

CVEs:CVE-2026-65358

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-43690

macOSCoalition ESS < 30%MEDIUM2026-09-14

A race condition was addressed with improved locking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A local user may be able to read kernel memory.

CVEs:CVE-2026-43690

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-84630

visionOSCoalition ESS < 30%MEDIUM2026-09-14

A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to caus...

CVEs:CVE-2026-84630

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-84562

macOSCoalition ESS < 30%MEDIUM2026-09-14

A race condition was addressed with additional validation. This issue is fixed in macOS Tahoe 26.6. An app may be able to access protected user data.

CVEs:CVE-2026-84562

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-86882

visionOSEPSS <= 49%CRITICAL2026-09-14

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a ...

CVEs:CVE-2026-86882

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-86895

visionOSEPSS <= 49%HIGH2026-09-14

An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27, watchOS 27. A local app may be able to read a persistent account identifier.

CVEs:CVE-2026-86895

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-86870

visionOSEPSS <= 49%CRITICAL2026-09-14

A heap buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27, watchOS 27. Processing a maliciously crafted file may lead to unexpected app t...

CVEs:CVE-2026-86870

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-86904

iPadOSEPSS <= 49%HIGH2026-09-14

A privacy issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, watchOS 27. An app may be able to track users across apps and websites without permission.

CVEs:CVE-2026-86904

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-86881

visionOSEPSS <= 49%CRITICAL2026-09-14

A certificate validation issue was addressed with improved certificate validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An a...

CVEs:CVE-2026-86881

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-86879

iPadOSEPSS <= 49%HIGH2026-09-14

A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27. A remote attacker may be able to cause a denial-of-service.

CVEs:CVE-2026-86879

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2026-86900

macOSEPSS <= 49%HIGH2026-09-14

An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27. Mounting a maliciously crafted exFAT volume may cause unexpected system termination or kernel memory disclosure.

CVEs:CVE-2026-86900

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-86869

iPadOSEPSS <= 49%CRITICAL2026-09-14

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, macOS Golden Gate 27. Processing a maliciously crafted image may lead to unexpected app termination.

CVEs:CVE-2026-86869

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-86894

macOSEPSS <= 49%HIGH2026-09-14

A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27. An app may be able to break out of its sandbox.

CVEs:CVE-2026-86894

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-86898

visionOSEPSS <= 49%CRITICAL2026-09-14

A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. Opening a maliciously crafted webarchive file may lead to universal cross-site scripting.

CVEs:CVE-2026-86898

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
safari affected apple — —
visionos affected apple — —
Upstream advisory

CVE-2026-86885

iPadOSEPSS <= 49%MEDIUM2026-09-14

An input validation issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27. An attacker in radio range may be able to cause unexpected system termination.

CVEs:CVE-2026-86885

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2026-86891

watchOSEPSS <= 49%LOW2026-09-14

An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, watchOS 27. An app may be able to access Bluetooth device information.

CVEs:CVE-2026-86891

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-86890

iPadOSEPSS <= 49%MEDIUM2026-09-14

A logic issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27. An attacker with physical access to a locked device may be able to view sensitive user information.

CVEs:CVE-2026-86890

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2026-86889

macOSEPSS <= 49%HIGH2026-09-14

A certificate validation issue was addressed with improved certificate validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker in a privileged network position may be able to intercept network traffic.

CVEs:CVE-2026-86889

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-86902

macOSEPSS <= 49%MEDIUM2026-09-14

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sonoma 14.8.8. An app may be able to access sensitive user data.

CVEs:CVE-2026-86902

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-86910

macOSEPSS <= 49%MEDIUM2026-09-14

A permissions issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An application may be able to access restricted files.

CVEs:CVE-2026-86910

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-86901

macOSEPSS <= 49%CRITICAL2026-09-14

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27. Mounting a maliciously crafted exFAT volume may cause unexpected system termination or kernel memory disclosure.

CVEs:CVE-2026-86901

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-86886

iPadOSEPSS <= 49%HIGH2026-09-14

A path traversal issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, watchOS 27. An app may be able to modify protected system files.

CVEs:CVE-2026-86886

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-86924

iPadOSEPSS <= 49%CRITICAL2026-09-14

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7. Connecting a malicious accessory may cause unexpected system terminat...

CVEs:CVE-2026-86924

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2026-86903

visionOSEPSS <= 49%MEDIUM2026-09-14

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to disclose kernel memory.

CVEs:CVE-2026-86903

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-86887

visionOSEPSS <= 49%HIGH2026-09-14

A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS 27. An app may be able to bypass certain Privacy preferences.

CVEs:CVE-2026-86887

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
visionos affected apple — —
Upstream advisory

CVE-2026-86897

visionOSEPSS <= 49%MEDIUM2026-09-14

This issue was addressed with additional entitlement checks. This issue is fixed in Safari 27, iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. An app may be able to access sensitive user data.

CVEs:CVE-2026-86897

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
safari affected apple — —
visionos affected apple — —
Upstream advisory

CVE-2026-86876

visionOSEPSS <= 49%CRITICAL2026-09-14

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, watchOS 27. A sandboxed process ma...

CVEs:CVE-2026-86876

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-86883

visionOSEPSS <= 49%MEDIUM2026-09-14

A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 27 and iPadOS 27, visionOS 27. An app may be able to access sensitive user data.

CVEs:CVE-2026-86883

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
visionos affected apple — —
Upstream advisory

CVE-2026-86917

macOSEPSS <= 49%CRITICAL2026-09-14

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.

CVEs:CVE-2026-86917

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-86909

macOSEPSS <= 49%MEDIUM2026-09-14

A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to bypass Gatekeeper checks.

CVEs:CVE-2026-86909

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-86911

macOSEPSS <= 49%MEDIUM2026-09-14

This issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. A malicious app may be able to bypass clickjacking protections for secure prompts.

CVEs:CVE-2026-86911

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2026-86878

iPadOSEPSS <= 49%MEDIUM2026-09-14

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27. An app may be able to access sensitive user data.

CVEs:CVE-2026-86878

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2026-86892

visionOSEPSS <= 49%HIGH2026-09-14

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS 27. An app may be able to cause a denial-of-service.

CVEs:CVE-2026-86892

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
visionos affected apple — —
Upstream advisory

CVE-2026-86888

visionOSEPSS <= 49%LOW2026-09-14

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A local app may be able to read a persistent account identifier.

CVEs:CVE-2026-86888

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-86884

iPadOSEPSS <= 49%MEDIUM2026-09-14

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27. An app may be able to access sensitive user data.

CVEs:CVE-2026-86884

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2026-86905

visionOSEPSS <= 49%MEDIUM2026-09-14

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. An app may be able to delete credentials stored in Keychain.

CVEs:CVE-2026-86905

Affected products

ProductStatusVendorPackageEcosystem
iOS and iPadOS affected Apple — —
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
visionos affected apple — —
Upstream advisory

CVE-2026-86893

visionOSEPSS <= 49%LOW2026-09-14

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to read device name.

CVEs:CVE-2026-86893

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
tvos affected apple — —
visionos affected apple — —
watchos affected apple — —
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.