For our customers' protection, Apple doesn't disclose, discuss, aliases corroborate information issues until an investigation has occurred and patches aliases releases are available. Recent releases are listed connected the Apple information releases page.
Apple information documents reference vulnerabilities by CVE-ID erstwhile possible.
For much accusation astir security, spot the Apple Product Security page.
Released July 27, 2026
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to entree delicate personification data
Description: An entree rumor was addressed pinch further sandbox restrictions.
CVE-2026-43819: Omar Cerrito
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to summation guidelines privileges
Description: A parsing rumor successful the handling of directory paths was addressed pinch improved way validation.
CVE-2026-43749: Adam Franke, Ashish Kunwar, Trung Nguyen (@everping) of CyStack
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to fingerprint the user
Description: This rumor was addressed pinch improved information protection.
CVE-2026-64733: Rosyna Keller of Totally Not Malicious Software (paradisefacade.com)
Available for: macOS Tahoe
Impact: A distant attacker whitethorn beryllium capable to origin unexpected strategy termination aliases corrupt kernel memory
Description: A buffer overflow was addressed pinch improved bounds checking.
CVE-2026-64767: Dave G.
Available for: macOS Tahoe
Impact: A distant attacker whitethorn beryllium capable to origin a denial-of-service
Description: This is simply a vulnerability successful unfastened root codification and Apple Software is among the affected projects. The CVE-ID was assigned by a 3rd party. Learn much astir the rumor and CVE-ID astatine cve.org.
CVE-2026-23918: Юлия Мерцалова
Available for: macOS Tahoe
Impact: A distant personification whitethorn beryllium capable to origin unexpected strategy termination aliases corrupt kernel memory
Description: The rumor was addressed pinch improved representation handling.
CVE-2026-64695: Peter Malone
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to entree delicate personification data
Description: This rumor was addressed pinch improved checks.
CVE-2026-43801: Rahul Raj
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to entree delicate personification data
Description: A title information was addressed pinch improved authorities handling.
CVE-2026-43781: Pinak Oza
Available for: macOS Tahoe
Impact: A malicious app whitethorn beryllium capable to break retired of its sandbox
Description: An authorization rumor was addressed pinch improved authorities management.
CVE-2026-64737: Robert Mindo
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin unexpected strategy termination
Description: An out-of-bounds constitute rumor was addressed pinch improved bounds checking.
CVE-2026-43748: an anonymous researcher, tamdao, Franco Belman astatine Blackwing Intelligence
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin unexpected strategy termination
Description: A usage aft free rumor was addressed pinch improved representation management.
CVE-2026-28928: Dun
Available for: macOS Tahoe
Impact: Processing a maliciously crafted record whitethorn lead to unexpected app termination aliases arbitrary codification execution
Description: A buffer overflow was addressed pinch improved bounds checking.
CVE-2026-43776: Irvin Wang, Peter Malone, Nicolas Rabrenovic
Available for: macOS Tahoe
Impact: A section personification whitethorn beryllium capable to publication kernel memory
Description: A buffer overflow was addressed pinch improved bounds checking.
CVE-2026-43681: impost0r (ret2plt), David Ige - Beryllium Security
Available for: macOS Tahoe
Impact: A malicious exertion whitethorn beryllium capable to bypass Privacy preferences
Description: An authorization rumor was addressed pinch improved authorities management.
CVE-2026-43672: 이재영
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to publication files extracurricular of its sandbox
Description: A permissions rumor was addressed by removing the susceptible code.
CVE-2026-43763: Pavan Nallamothu, Jared Reyes
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to break retired of its sandbox
Description: An entree rumor was addressed pinch further sandbox restrictions.
CVE-2026-64702: John Lussier
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin a denial-of-service
Description: An out-of-bounds constitute rumor was addressed pinch improved bounds checking.
CVE-2026-64725: Seonung Park, ALTV!ST (altvi.st/)
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to fingerprint the user
Description: A permissions rumor was addressed pinch further restrictions.
CVE-2026-43730: David Strnadel
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to execute arbitrary codification pinch kernel privileges
Description: A buffer overflow was addressed pinch improved size validation.
CVE-2026-64747: Franco Belman astatine Blackwing Intelligence
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin unexpected strategy termination
Description: An out-of-bounds publication was addressed pinch improved bounds checking.
CVE-2026-64762: Dun, Franco Belman astatine Blackwing Intelligence
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to delete files for which it does not person permission
Description: A permissions rumor was addressed pinch improved validation.
CVE-2026-64707: YingQi Shi (@Mas0nShi) of DBAppSecurity's WeBin lab
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin unexpected strategy termination aliases publication kernel memory
Description: The rumor was addressed pinch improved representation handling.
CVE-2026-64698: an anonymous researcher, Richard Zana, Nathaniel Oh (@calysteon), Peter Malone
Available for: macOS Tahoe
Impact: A maliciously crafted app whitethorn beryllium capable to bypass codification signing enforcement
Description: A validation rumor was addressed pinch improved input sanitization.
CVE-2026-43813: Anton Pakhunov
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to adhd contacts without personification authorization
Description: An authorization rumor was addressed pinch improved validation.
CVE-2026-64746: Rodolphe BRUNETTI (@eisw0lf) of Lupus Nova, Daniel Febrero
Available for: macOS Tahoe
Impact: Processing a maliciously crafted interaction whitethorn leak delicate data
Description: The rumor was addressed pinch improved checks.
CVE-2026-64734: Daniel Williams
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to entree accusation astir a user's contacts
Description: This rumor was addressed pinch improved checks.
CVE-2026-43797: Arni Hardarson (Neonix Security)
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to entree user-sensitive data
Description: A logic rumor was addressed pinch improved validation.
CVE-2026-43756: 이재영
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to summation guidelines privileges
Description: A title information was addressed pinch improved authorities handling.
CVE-2026-43693: Gergely Kalman (@gergely_kalman)
Available for: macOS Tahoe
Impact: Processing a maliciously crafted audio record whitethorn corrupt process memory
Description: The rumor was addressed pinch improved representation handling.
CVE-2026-43673: Anonymous moving pinch TrendAI Zero Day Initiative
Available for: macOS Tahoe
Impact: Processing an audio watercourse successful a maliciously crafted media record whitethorn terminate the process
Description: An out-of-bounds constitute rumor was addressed pinch improved bounds checking.
CVE-2026-43744: Mathis Mansière, an anonymous researcher
Available for: macOS Tahoe
Impact: A distant attacker whitethorn beryllium capable to origin unexpected strategy termination
Description: An out-of-bounds constitute rumor was addressed pinch improved bounds checking.
CVE-2026-43803: Rahul Raj
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to entree delicate personification data
Description: An authorization rumor was addressed pinch improved authorities management.
CVE-2026-43775: Csaba Fitzl (@theevilbit) of Iru
CVE-2026-43759: 이재영, Rajdip Dey Sarkar, Arni Hardarson (Neonix Security)
Available for: macOS Tahoe
Impact: Processing a maliciously crafted video record whitethorn lead to unexpected app termination
Description: A representation corruption rumor was addressed pinch improved representation handling.
CVE-2026-43711: James Duffy (@0x4A616D657344)
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin unexpected strategy termination
Description: An out-of-bounds constitute rumor was addressed pinch improved bounds checking.
CVE-2026-43802: an anonymous researcher
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to leak delicate personification information
Description: A privateness rumor was addressed by removing delicate data.
CVE-2026-64710: Matthew Schneider
Available for: macOS Tahoe
Impact: A malicious app whitethorn beryllium capable to summation guidelines privileges
Description: A permissions rumor was addressed pinch further restrictions.
CVE-2026-39875: Dallas Dubs, Aaron Grattafiori - NVIDIA AI Red Team, XBreach.ai, Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to summation guidelines privileges
Description: An injection rumor was addressed pinch improved validation.
CVE-2026-43698: Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs
Available for: macOS Tahoe
Impact: Authentication credentials whitethorn beryllium sent to a server connected different origin
Description: This is simply a vulnerability successful unfastened root codification and Apple Software is among the affected projects. The CVE-ID was assigned by a 3rd party. Learn much astir the rumor and CVE-ID astatine cve.org.
CVE-2026-3784
CVE-2026-3783
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to entree delicate personification data
Description: An authorization rumor was addressed pinch improved authorities management.
CVE-2026-43758: HvxyZLF
Available for: macOS Tahoe
Impact: An app whitethorn bypass Gatekeeper checks
Description: A record quarantine bypass was addressed pinch further checks.
CVE-2026-64708: Lance Cain - Offensive Security Engineer, SpecterOps Inc.
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to disclose kernel memory
Description: The rumor was addressed pinch improved bounds checks.
CVE-2026-64776: Hyunwoo Kim (@v4bel)
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin unexpected strategy termination
Description: An integer overflow was addressed pinch improved input validation.
CVE-2026-64694: Gil Portnoy & Henry
Available for: macOS Tahoe
Impact: Parsing a maliciously crafted record whitethorn lead to an unexpected app termination
Description: An out-of-bounds publication was addressed pinch improved bounds checking.
CVE-2026-43747: Anthony Laou Hine Tsuei (@anarcheuz)
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to bypass web restrictions
Description: A permissions rumor was addressed pinch further sandbox restrictions.
CVE-2026-28945: Ayaan Ahmad
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin unexpected strategy termination
Description: An rumor existed successful the handling of situation variables. This rumor was addressed pinch improved validation.
CVE-2026-43793: erdene-och Byambabayar
Available for: macOS Tahoe
Impact: An attacker pinch beingness entree to a locked instrumentality whitethorn beryllium capable to position delicate personification information
Description: An out-of-bounds publication was addressed pinch improved bounds checking.
CVE-2026-43753: Niels Hofmans
Available for: macOS Tahoe
Impact: A malicious app whitethorn beryllium capable to entree protected personification data
Description: The rumor was addressed pinch improved input sanitization.
CVE-2026-43714: an anonymous researcher
Available for: macOS Tahoe
Impact: A malicious app whitethorn beryllium capable to break retired of its sandbox
Description: A parsing rumor successful the handling of directory paths was addressed pinch improved way validation.
CVE-2026-64740: Manuel Fernandez (Stackhopper Security)
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to entree delicate personification data
Description: This rumor was addressed pinch improved information protection.
CVE-2026-43796: Ilya Andr (andrd3v) of Positive Technologies, Stanislav Jelezoglo
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin unexpected strategy termination
Description: A buffer overflow was addressed pinch improved size validation.
CVE-2026-64691: Somair Ansar, Josh Maine of Calif.io, Johnny Franks (@zeroxjf), hxr1, Alexandre Soleiman, Alexander Tarasikov and Ruslan Dautov, Ruslan Dautov
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin a denial-of-service
Description: An out-of-bounds publication was addressed pinch improved bounds checking.
CVE-2026-64692: Redon Gashi
Available for: macOS Tahoe
Impact: A distant personification whitethorn beryllium capable to origin unexpected strategy termination aliases corrupt kernel memory
Description: The rumor was addressed pinch improved representation handling.
CVE-2026-43682: Trung Nguyen (@everping) of CyStack, Dave G., Nicolas Rabrenovic, Atul R V & Ashmit Sharma, Peter Malone
Available for: macOS Tahoe
Impact: Processing a maliciously crafted image whitethorn lead to arbitrary codification execution
Description: A buffer overflow was addressed pinch improved bounds checking.
CVE-2026-28981: Hcamael and 章鱼哥@aipy (aipyaipy.com), Aswin Kumar Gokulakannan, Surya Narayan Kushwaha, Dun
Available for: macOS Tahoe
Impact: Mounting a maliciously crafted disk image whitethorn origin unexpected strategy termination aliases corrupt kernel memory
Description: An out-of-bounds publication was addressed pinch improved bounds checking.
CVE-2026-43773: Richard Zana, Peter Malone, Surya Narayan Kushwaha, Hyunwoo Kim (@v4bel), Cem Onat Karagun
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin unexpected strategy termination
Description: The rumor was addressed pinch improved representation handling.
CVE-2026-43767: Hyunwoo Kim (@v4bel)
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin unexpected strategy termination
Description: An integer overflow was addressed pinch improved input validation.
CVE-2026-43764: Tristan Madani (@TristanInSec) from Talence Security
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin unexpected strategy termination aliases corrupt kernel memory
Description: The rumor was addressed pinch improved representation handling.
CVE-2026-64697: Peter Malone
Available for: macOS Tahoe
Impact: An attacker whitethorn beryllium capable to origin unexpected strategy termination aliases corrupt kernel memory
Description: The rumor was addressed pinch improved representation handling.
CVE-2026-43710: Peter Malone
Available for: macOS Tahoe
Impact: Processing a maliciously crafted texture whitethorn lead to unexpected app termination
Description: An integer overflow was addressed pinch improved input validation.
CVE-2026-43780: Michael DePlante (@izobashi) of TrendAI Zero Day Initiative
Available for: macOS Tahoe
Impact: Processing a maliciously crafted image whitethorn lead to arbitrary codification execution
Description: An integer overflow was addressed pinch improved input validation.
CVE-2026-43818: an anonymous researcher
Available for: macOS Tahoe
Impact: Processing a maliciously crafted image whitethorn corrupt process memory
Description: The rumor was addressed pinch improved representation handling.
CVE-2026-64716: Arni Hardarson, Jonathan Alush-Aben, Peter Malone
Available for: macOS Tahoe
Impact: Processing a maliciously crafted record whitethorn lead to unexpected app termination
Description: The rumor was addressed pinch improved bounds checks.
CVE-2026-64758: 진규정 (Gyujeong Jin, @G1uN4sh)
Available for: macOS Tahoe
Impact: Processing a maliciously crafted record whitethorn lead to a denial-of-service
Description: An out-of-bounds constitute rumor was addressed pinch improved bounds checking.
CVE-2026-64754: PETOWORKS의 Bugeun Choi (@Bugeun), Rahul Raj
Available for: macOS Tahoe
Impact: Processing a maliciously crafted image whitethorn lead to a denial-of-service
Description: A type disorder rumor was addressed pinch improved checks.
CVE-2026-64693: Geonha Lee (@leegn4a)
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin unexpected strategy termination aliases constitute kernel memory
Description: A title information was addressed pinch improved authorities handling.
CVE-2026-43805: 이재영
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to entree delicate personification data
Description: This rumor was addressed pinch improved checks.
CVE-2026-43782: Igor Ushakov
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin unexpected strategy termination aliases corrupt kernel memory
Description: The rumor was addressed pinch improved representation handling.
CVE-2026-64749: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Ashish Kunwar, Hiroki Imai (LAC Co., Ltd.), hxr1
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to disclose kernel memory
Description: An accusation leakage was addressed pinch further validation.
CVE-2026-64744: Ryan Hileman via Xint Code (xint.io)
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin unexpected strategy termination aliases corrupt kernel memory
Description: A usage aft free rumor was addressed pinch improved representation management.
CVE-2026-43778: f0r of MurphySec, Feng Xue and XGPT of ThreatBook, Mahmoud Abdelmoniem, an anonymous researcher, Wang Yu, Lyutoon, Hiroki Imai (LAC Co., Ltd.), DARKNAVY (@DarkNavyOrg), Fábio Luís @scanpt, Nicolas Rabrenovic
Available for: macOS Tahoe
Impact: A distant personification whitethorn beryllium capable to origin unexpected strategy termination aliases corrupt kernel memory
Description: A title information was addressed pinch improved locking.
CVE-2026-28982: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Adam Doupé of ASU SEFCOM
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to disclose kernel memory
Description: The rumor was addressed pinch improved representation handling.
CVE-2026-64709: Pasquale Scola, Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.
Available for: macOS Tahoe
Impact: A distant attacker whitethorn beryllium capable to bypass web filters
Description: An inconsistent personification interface rumor was addressed pinch improved authorities management.
CVE-2026-64735: Gor Aleksanyan
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin unexpected strategy termination
Description: An out-of-bounds constitute rumor was addressed pinch improved bounds checking.
CVE-2026-43739: impost0r (ret2plt), Ruslan Dautov, Aleksandr Tarasikov, jay, Dhiyanesh Selvaraj (@redroot97), Vinay Kumar Rasala (Xplo8E) from Appknox, Lyutoon, DongJun Kim (smlijun) pinch UIUC, Hwiwon Lee (hwiwonl) pinch UIUC, Jongseong Kim (nevul37) pinch UIUC, Younggi Park (grill66) pinch UIUC, Peter Malone, an anonymous researcher, Hari Shanmugam (The Hxr1), Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Marco Grassi, Dun, Daniele Castronovo, Michal Kosiorek
CVE-2026-43816: Josh Maine of Calif.io, Ruslan Dautov, 재영 정, @rootxran (Rao Ali Nawaz), Chanwit Muenprakoddee (ChemIndy), an anonymous researcher, Ye Zhang (@VAR10CK) of Baidu Security, Franco Belman astatine Blackwing Intelligence, Christian Figueroa, Johnny Franks (@zeroxjf), Ashmit Sharma & Atul RV, Peter Malone, Muhamad Syaiful, Muneeb Amin Bhat, Dhiyanesh Selvaraj (@redroot97), Ali Marzouq, Bountyy Oy - Mihalis Haatainen, Huy Nguyen (@34306) of Calif.io
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin unexpected strategy termination
Description: A usage aft free rumor was addressed pinch improved representation management.
CVE-2026-43822: Eddy Tsalolikhin, Michal Kosiorek
CVE-2026-64729: Josh Maine of Calif.io, beist, Adam Doupé of ASU SEFCOM, Dun, Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Johnny Franks (@zeroxjf)
CVE-2026-43814: Somair Ansar, Huy Nguyen (@34306) of Calif.io
CVE-2026-64700: Asjid Kalam (@odinshell)
CVE-2026-43799: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.
Available for: macOS Tahoe
Impact: Connecting to a malicious NFS server whitethorn lead to kernel representation corruption
Description: A buffer overflow was addressed pinch improved bounds checking.
CVE-2026-28931: Redon Gashi, Abhijeet Singh (linkedin.com/in/abhiunix/), Peter Malone, Omar Cerrito
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin unexpected strategy termination
Description: An out-of-bounds publication was addressed pinch improved bounds checking.
CVE-2026-43817: Huy Nguyen (@34306) of Calif.io
CVE-2026-43809: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.
CVE-2026-43757: Wang Yu, Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin unexpected strategy termination
Description: An integer overflow was addressed pinch improved input validation.
CVE-2026-43769: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin unexpected strategy termination
Description: A type disorder rumor was addressed pinch improved representation handling.
CVE-2026-64727: Ye Zhang (@VAR10CK) of Baidu Security
Available for: macOS Tahoe
Impact: A distant personification whitethorn beryllium capable to origin unexpected strategy termination aliases corrupt kernel memory
Description: The rumor was addressed pinch improved representation handling.
CVE-2026-43810: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin unexpected strategy termination
Description: A representation initialization rumor was addressed pinch improved representation handling.
CVE-2026-64775: Ryan Hileman via Xint Code (xint.io)
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to entree delicate personification data
Description: A logic rumor was addressed pinch improved checks.
CVE-2026-64723: Ji'an Zhou, Mingxuan Yang, Ye Zhang
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin unexpected strategy termination
Description: A title information was addressed pinch improved authorities handling.
CVE-2026-64720: an anonymous researcher, Asjid Kalam (@odinshell), Jian Zhou and Ye Zhang
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to leak delicate kernel state
Description: This rumor was addressed pinch improved redaction of delicate information.
CVE-2026-43754: Calif Research, Ernesto Martínez García
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin unexpected strategy termination aliases constitute kernel memory
Description: A usage aft free rumor was addressed pinch improved representation management.
CVE-2026-64751: N.M.Praveen Nawarathne (@zblockrat)
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to entree delicate personification data
Description: This rumor was addressed done improved authorities management.
CVE-2026-64721: Lukas Gerlach
Available for: macOS Tahoe
Impact: Processing a maliciously crafted record whitethorn consequence successful disclosure of process memory
Description: This is simply a vulnerability successful unfastened root codification and Apple Software is among the affected projects. The CVE-ID was assigned by a 3rd party. Learn much astir the rumor and CVE-ID astatine cve.org.
CVE-2026-4424
Available for: macOS Tahoe
Impact: A malicious app whitethorn beryllium capable to break retired of its sandbox
Description: An integer overflow was addressed pinch improved input validation.
CVE-2026-28973: an anonymous researcher
Available for: macOS Tahoe
Impact: An attacker whitethorn beryllium capable to origin unexpected app termination
Description: An out-of-bounds constitute rumor was addressed pinch improved bounds checking.
CVE-2026-64739: Feng Xue and XGPT of ThreatBook, Dun
Available for: macOS Tahoe
Impact: An attacker pinch beingness entree to a locked instrumentality whitethorn beryllium capable to position delicate personification information
Description: An authorization rumor was addressed pinch improved authorities management.
CVE-2026-43766: Amy (amys.website)
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to entree delicate personification data
Description: An authorization rumor was addressed pinch improved authorities management.
CVE-2026-64743: Daniel Febrero
Available for: macOS Tahoe
Impact: A malicious app whitethorn beryllium capable to break retired of its sandbox
Description: A permissions rumor was addressed pinch further restrictions.
CVE-2026-64738: Nathaniel Oh (@calysteon), Robert Mindo
Available for: macOS Tahoe
Impact: A section attacker whitethorn beryllium capable to origin a denial of service
Description: A denial of work rumor was addressed by removing the susceptible code.
CVE-2026-43806: He Wei (ギカク), 章鱼哥 (@aipy) of aipyaipy.com, Jex Amro, Cem Onat Karagun
Available for: macOS Tahoe
Impact: An attacker connected the section web whitethorn beryllium capable to origin a denial-of-service
Description: The rumor was addressed pinch improved representation handling.
CVE-2026-64724: Daisuke Hatakeyama (@SYZD Research)
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to summation guidelines privileges
Description: A way handling rumor was addressed pinch improved validation.
CVE-2026-43723: Richard Zana, Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs
Available for: macOS Tahoe
Impact: A malicious app whitethorn beryllium capable to corrupt representation of a strategy process
Description: The rumor was addressed pinch improved representation handling.
CVE-2026-28911: yk lin of @pixiepointsec
Available for: macOS Tahoe
Impact: Processing a maliciously crafted image whitethorn corrupt process memory
Description: The rumor was addressed pinch improved representation handling.
CVE-2026-43733: Michael DePlante (@izobashi) of TrendAI Zero Day Initiative
CVE-2026-43729: Michael DePlante (@izobashi) of TrendAI Zero Day Initiative
Available for: macOS Tahoe
Impact: A distant attacker whitethorn beryllium capable to origin unexpected exertion termination aliases heap corruption
Description: An out-of-bounds constitute rumor was addressed pinch improved input validation.
CVE-2026-64772: stratan (@5tratan), wh0am1i
Available for: macOS Tahoe
Impact: A distant attacker whitethorn beryllium capable to origin unexpected exertion termination aliases heap corruption
Description: A buffer overflow was addressed pinch improved bounds checking.
CVE-2026-64771: wh0am1i
Available for: macOS Tahoe
Impact: Processing a 3D exemplary whitethorn consequence successful disclosure of process memory
Description: A buffer overflow rumor was addressed pinch improved representation handling.
CVE-2026-64722: wh0am1i
Available for: macOS Tahoe
Impact: A distant attacker whitethorn beryllium capable to origin unexpected exertion termination aliases heap corruption
Description: An integer overflow was addressed pinch improved input validation.
CVE-2026-64774: stratan (@5tratan)
Available for: macOS Tahoe
Impact: A distant attacker whitethorn beryllium capable to origin unexpected exertion termination aliases heap corruption
Description: An out-of-bounds constitute rumor was addressed pinch improved bounds checking.
CVE-2026-64770: stratan (@5tratan)
CVE-2026-64769: stratan (@5tratan)
Available for: macOS Tahoe
Impact: A distant attacker whitethorn origin an unexpected app termination
Description: An out-of-bounds publication rumor was addressed pinch improved input validation.
CVE-2026-64768: stratan (@5tratan)
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin a denial-of-service
Description: A stack overflow was addressed pinch improved input validation.
CVE-2026-43771: Robert Tran
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to break retired of its sandbox
Description: A way traversal rumor was addressed pinch improved input validation.
CVE-2026-43772: Mickey Jin (@patch1t)
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to leak delicate personification information
Description: This rumor was addressed pinch further entitlement checks.
CVE-2026-64711: Koh M. Nakagawa (@tsunek0h) of FFRI Security, Inc.
Available for: macOS Tahoe
Impact: A personification whitethorn beryllium capable to elevate privileges
Description: A logic rumor was addressed pinch improved restrictions.
CVE-2026-28912: Matej Moravec (@MacejkoMoravec)
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to modify protected parts of the record system
Description: This rumor was addressed pinch improved handling of symlinks.
CVE-2026-43765: Mickey Jin (@patch1t)
Available for: macOS Tahoe
Impact: A malicious app whitethorn beryllium capable to break retired of its sandbox
Description: A way handling rumor was addressed pinch improved validation.
CVE-2026-64731: Sindre Sorhus, Richard Zana
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin unexpected strategy termination
Description: A usage aft free rumor was addressed pinch improved representation management.
CVE-2026-43812: Francisco Knabe
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin unexpected strategy termination aliases constitute kernel memory
Description: The rumor was addressed pinch improved representation handling.
CVE-2026-43694: Hcamael and 章鱼哥@aipy (aipyaipy.com), JC Alvarado of Stripe, Jacob Hazak
Available for: macOS Tahoe
Impact: A malicious app whitethorn beryllium capable to summation guidelines privileges
Description: A permissions rumor was addressed pinch further restrictions.
CVE-2026-39874: @pixiepointsec
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to entree delicate personification data
Description: An authorization rumor was addressed pinch improved authorities management.
CVE-2026-43792: Ilya Andr (andrd3v)
Available for: macOS Tahoe
Impact: Processing a maliciously crafted record whitethorn lead to unexpected app termination aliases arbitrary codification execution
Description: An integer overflow was addressed pinch improved input validation.
CVE-2026-64766: stratan (@5tratan)
CVE-2026-64765: stratan (@5tratan)
Impact: Processing a maliciously crafted record whitethorn lead to unexpected app termination aliases arbitrary codification execution
Description: An out-of-bounds constitute rumor was addressed pinch improved bounds checking.
CVE-2026-64764: stratan (@5tratan)
Available for: macOS Tahoe
Impact: Processing a maliciously crafted record whitethorn lead to unexpected app termination aliases arbitrary codification execution
Description: An out-of-bounds constitute rumor was addressed by removing the susceptible code.
CVE-2026-64763: stratan (@5tratan)
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to intercept web connections intended for different process
Description: A logic rumor was addressed pinch improved restrictions.
CVE-2026-43779: Dave G., Asaf Cohen
Available for: macOS Tahoe
Impact: A distant attacker whitethorn beryllium capable to origin a denial of service
Description: This rumor was addressed pinch improved input validation.
CVE-2026-43777: Junming C.(Chapoly1305)
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to entree user-sensitive data
Description: An entree rumor was addressed pinch improved entree restrictions.
CVE-2026-43760: Alfredo Pesoli (@__rev) of Bynar.io, wdszzml and Atuin Automated Vulnerability Discovery Engine
Available for: macOS Tahoe
Impact: An attacker whitethorn beryllium capable to modify the authorities of the Keychain
Description: This rumor was addressed done improved authorities management.
CVE-2026-43728: Bob Gendler of the National Institute of Standards and Technology
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to summation guidelines privileges
Description: A title information was addressed pinch improved authorities management.
CVE-2026-43755: Mickey Jin (@patch1t)
Available for: macOS Tahoe
Impact: A personification pinch beingness entree to a locked instrumentality whitethorn beryllium capable to entree contacts and photos
Description: This rumor was addressed pinch further restrictions connected the fastener screen.
CVE-2026-64745: Vivek Dhar, ASI (RM) successful Border Security Force, FTR HQ BSF Kashmir
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to entree delicate personification data
Description: An accusation disclosure rumor was addressed by removing the susceptible code.
CVE-2026-43800: Stanislav Jelezoglo
Available for: macOS Tahoe
Impact: Connecting to a malicious SMB server whitethorn lead to unexpected strategy termination
Description: The rumor was addressed pinch improved representation handling.
CVE-2026-39873: Peter Malone
Available for: macOS Tahoe
Impact: A distant personification whitethorn beryllium capable to origin unexpected strategy termination aliases corrupt kernel memory
Description: The rumor was addressed pinch improved representation handling.
CVE-2026-64696: Feng Xue and XGPT of ThreatBook, Peter Malone
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin unexpected strategy termination
Description: A type disorder rumor was addressed pinch improved representation handling.
CVE-2026-64704: Claudio Bozzato and Francesco Benvenuto of Cisco Talos, Aswin Kumar Gokulakannan, Kitten Food, Peter Malone, Calif.io successful collaboration pinch Claude and Anthropic Research
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to entree delicate personification data
Description: An out-of-bounds publication was addressed pinch improved bounds checking.
CVE-2026-43774: Csaba Fitzl (@theevilbit) of Iru
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to entree delicate personification data
Description: A title information was addressed pinch further validation.
CVE-2026-43770: Tien-Chih Lin of CyCraft Technology
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin unexpected strategy termination
Description: The rumor was addressed pinch improved representation handling.
CVE-2026-43768: Hyunwoo Kim (@v4bel)
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin a denial-of-service
Description: A usage aft free rumor was addressed pinch improved representation management.
CVE-2026-64703: Bruce Dang of Calif.io successful collaboration pinch Claude and Anthropic Research
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to disclose kernel memory
Description: A representation initialization rumor was addressed pinch improved representation handling.
CVE-2026-64699: Bruce Dang of Calif.io
Available for: macOS Tahoe
Impact: Processing maliciously crafted web contented whitethorn consequence successful the disclosure of process memory
Description: The rumor was addressed pinch improved representation handling.
WebKit Bugzilla: 308046
CVE-2026-43740: Arni Hardarson, Nathaniel Oh (@calysteon)
Available for: macOS Tahoe
Impact: Websites whitethorn cognize if the personification has visited a fixed link
Description: This rumor was addressed pinch improved checks.
WebKit Bugzilla: 316827
CVE-2026-64713: Kwak Kiyong, Song Nuri
Available for: macOS Tahoe
Impact: Visiting a website that frames malicious contented whitethorn lead to UI spoofing
Description: The rumor was addressed pinch improved UI.
WebKit Bugzilla: 311660
CVE-2026-64730: Kagami Rosylight of Mozilla
Available for: macOS Tahoe
Impact: Maliciously crafted web contented whitethorn break iframe sandboxing policy
Description: A permissions rumor was addressed pinch improved validation.
WebKit Bugzilla: 313220
CVE-2026-64728: an anonymous interrogator
Available for: macOS Tahoe
Impact: Processing maliciously crafted web contented whitethorn lead to an unexpected Safari crash
Description: A use-after-free rumor was addressed pinch improved representation management.
WebKit Bugzilla: 313521
CVE-2026-64783: 杉山 壮太, lattice, Behzad Najjarpour Jabbari (@_G4ru_), Junyeong Lee, Mooth.ai, OGINOME Tomohito, Using GLM From Z.AI, Gia Bui (@yabeow) from Calif.io
Available for: macOS Tahoe
Impact: Processing maliciously crafted web contented whitethorn lead to an unexpected Safari crash
Description: A representation corruption rumor was addressed pinch improved authorities management.
WebKit Bugzilla: 315082
CVE-2026-64757: Milad Nasr and Nicholas Carlini pinch Claude, Anthropic
Available for: macOS Tahoe
Impact: Visiting a website whitethorn lead to an app denial-of-service
Description: This rumor was addressed done improved authorities management.
WebKit Bugzilla: 316816
CVE-2026-43804: Heiko Kiesel of SEEMOO, TU Darmstadt
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to publication files extracurricular of its sandbox
Description: An entree rumor was addressed pinch improved entree restrictions.
WebKit Bugzilla: 314867
CVE-2026-43821: Brian Carpenter
Available for: macOS Tahoe
Impact: Processing maliciously crafted web contented whitethorn lead to an unexpected Safari crash
Description: A use-after-free rumor was addressed pinch improved representation management.
WebKit Bugzilla: 313935
CVE-2026-64718: OGINOME Tomohito, an anonymous researcher
Available for: macOS Tahoe
Impact: Processing maliciously crafted web contented whitethorn lead to an unexpected Safari crash
Description: An out-of-bounds entree rumor was addressed pinch improved bounds checking.
WebKit Bugzilla: 319404
CVE-2026-64719: Shaheen Fazim
Available for: macOS Tahoe
Impact: An attacker successful beingness proximity whitethorn beryllium capable to corrupt process memory
Description: The rumor was addressed pinch improved representation handling.
CVE-2026-64726: Mathis Mansière, Peter Malone
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to execute arbitrary codification retired of its sandbox aliases pinch definite elevated privileges
Description: A buffer overflow was addressed pinch improved bounds checking.
CVE-2026-43750: an anonymous researcher
Available for: macOS Tahoe
Impact: An app whitethorn beryllium capable to origin a denial of service
Description: A logic rumor existed resulting successful representation corruption. This was addressed pinch improved authorities management.
CVE-2026-28932: Mathis Mansière
We would for illustration to admit Niels Hofmans for their assistance.
We would for illustration to admit Keisuke Hosoda for their assistance.
We would for illustration to admit Alan Banderas (@creeper4004) for their assistance.
We would for illustration to admit yaohway for their assistance.
We would for illustration to admit Surya Narayan Kushwaha for their assistance.
We would for illustration to admit Jordy Zomer (@pwningsystems), Phillip Groves, Richard Zana for their assistance.
We would for illustration to admit Niels Hofmans for their assistance.
We would for illustration to admit Nick Cook, Sentry Flag for their assistance.
We would for illustration to admit Surya Narayan Kushwaha for their assistance.
We would for illustration to admit Aswin Kumar Gokula Kannan, Surya Narayan Kushwaha, Yatin Taneja for their assistance.
We would for illustration to admit Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Chris Betz, Hiroki Imai (LAC Co., Ltd.), James Duffy ( @0x4A616D657344 ), Mathis Mansière, Tristan Rousseau, Vladislav Shevchenko (Positive Technologies), Yeojin Kim, YingMuo (@YingMuo) of DEVCORE Research Team for their assistance.
We would for illustration to admit Asaf Cohen, Ashish Kunwar for their assistance.
We would for illustration to admit Jacolon Walker ( @call_eax ) for their assistance.
We would for illustration to admit Maliq Barnard, Tommy DeVoss from Braze Security Team (@thedawgyg), Willard Jansen for their assistance.
We would for illustration to admit an anonymous interrogator for their assistance.
We would for illustration to admit Alfaz Hossain for their assistance.
We would for illustration to admit Ayaan Ahmad, XlabAI Team of Tencent Xuanwu Lab, Atuin Automated Vulnerability Discovery Engine, Guannan Wang, Zhanpeng Liu, Jiashuo Liang, Guancheng Li for their assistance.
We would for illustration to admit John Lussier, Oleh Konko of 1seal (1seal.org), alick for their assistance.
We would for illustration to admit Ilya Andr (andrd3v) and nkhmelni for their assistance.
We would for illustration to admit Masaki Moriguchi, Omar Cerrito for their assistance.
We would for illustration to admit Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs for their assistance.
We would for illustration to admit Jaya Surya Kommireddy, Jaya surya Kommireddy, Lukas Knittel (@kunte_ctf) of Ruhr-University Bochum, Nikos Fanourakis of Technical University of Crete, Sotiris Ioannidis of Technical University of Crete, Panagiotis Ilia of Cyprus University of Technology, and Kostas Drakonakis of Technical University of Crete, Tony Gorez (@tonygo_) for Reverse Society, Vitaly Simonovich, Youngjoon Kim of Team-Atlanta & sslab astatine Georgia Tech, s3zer0 for their assistance.
We would for illustration to admit Codex Security - Khai Tran, Daisuke Hatakeyama and Ryohei Ueki (@SYZD Research), David Bors astatine Snyk Security Labs, Giovanni Vignone and Robert van Eijk of Octane Security (octane.security), Kwak Kiyong, Song nuri, Luat Nguyen (CyberJutsu Academy), Tom Van Goethem, an anonymous researcher, dr3dd for their assistance.
We would for illustration to admit Gurpreet Shergill, Luke Francis, Milad Nasr and Nicholas Carlini pinch Claude, Anthropic, Oleh Konko of 1seal (1seal.org), Vitaly Simonovich for their assistance.
We would for illustration to admit Anurag Bohra of Microsoft, Cem Onat Karagun, Feng Xue and XGPT of ThreatBook, Kubilay Berk ALKAN, s3zer0 for their assistance.
We would for illustration to admit Ferdous Saljooki (@malwarezoo) of Jamf for their assistance.
Information astir products not manufactured by Apple, aliases independent websites not controlled aliases tested by Apple, is provided without proposal aliases endorsement. Apple assumes nary work pinch respect to the selection, performance, aliases usage of third-party websites aliases products. Apple makes nary representations regarding third-party website accuracy aliases reliability. Contact the vendor for further information.
Published Date: July 27, 2026
English (US) ·
Indonesian (ID) ·