Google Security Research
1,215 exploits
Active since May 2013
macOS < 10.15 and tvOS < 13 - Out-of-bounds Write
CVSS 7.8
macOS XNU - Missing Locking in checkdirs_callback() Enables Race with fchdir_common()
iPhone OS < 12.1.3, macOS < 10.14.3, tvOS < 12.1.2 - Memory Corruption via Improper Initialization
CVSS 5.5
macOS XNU - Copy-on-Write Behavior Bypass via Mount of User-Owned Filesystem Image
macOS < 10.13.3 - Memory Corruption and Remote Code Execution in Touch Bar Support
CVSS 7.8
macOS < 10.14.6 - Remote Code Execution via Use-After-Free
CVSS 9.8
macOS 10.14.6 (18G87) - Kernel Use-After-Free due to Race Condition in wait_for_namespace_event()
Apple <10.13.2 - Info Disclosure/DoS
CVSS 7.1
Apple tvOS < 11.2.5 - Kernel Memory Read Restriction Bypass
CVSS 5.5
Apple <11.2 - Privilege Escalation/DoS
CVSS 6.6
iPhone OS < 12.1.3, macOS < 10.14.3, tvOS < 12.1.2, watchOS < 5.1.3 - Remote Code Execution via FaceTime Call
CVSS 8.8
iPhone OS < 12.1 - Memory Corruption via Improved Input Validation
CVSS 7.5
iPhone OS < 12.1 - Memory Corruption via Improved Input Validation
CVSS 9.8
Apple <11.2, <10.13.2, <4.2, <11.2 - Info Disclosure
CVSS 5.5
iPhone OS < 10.3, macOS < 10.12.4, tvOS < 10.2, watchOS < 3.2 - Use-After-Free in Kernel
CVSS 7.8
iPhone OS < 10.3, macOS < 10.12.4, tvOS < 10.2, watchOS < 3.2 - Kernel Buffer Overflow via Crafted App
CVSS 7.8
macOS < 10.12.4 - Unauthorized Kernel Memory Exposure via Intel Graphics Driver
CVSS 5.5
macOS < 10.12.4 - Memory Corruption in Intel Graphics Driver
CVSS 7.8
macOS < 10.13.5 - Use-After-Free in NVIDIA Graphics Drivers via SetAppSupportBits Race Condition
CVSS 7.0
macOS < 10.13.4 - Remote Code Execution in kext tools
CVSS 7.8
macOS < 10.12.2 - Remote Code Execution or Denial of Service via Bluetooth Type Confusion
CVSS 7.8
macOS < 10.12.2 - Use-After-Free in Directory Services
CVSS 7.8
macOS < 10.12.5 - Remote Code Execution in Accessibility Framework
CVSS 7.8
macOS < 10.13.2 - Out-of-bounds Read in Intel Graphics Driver
CVSS 7.8
macOS < 10.12.5 - Kernel Memory Read Restriction Bypass via Crafted App
CVSS 5.0