Apple Vulnerabilities and Affected Products
Vulnerabilities associated with macOS.
Products
Clear product- macOS3,219 vulnerabilities
- iOS and iPadOS1,660 vulnerabilities
- watchOS1,278 vulnerabilities
- tvOS1,206 vulnerabilities
- visionOS554 vulnerabilities
- iOS511 vulnerabilities
- Safari465 vulnerabilities
- iTunes for Windows192 vulnerabilities
- iPadOS185 vulnerabilities
- iCloud for Windows181 vulnerabilities
- iCloud for Windows (Legacy)75 vulnerabilities
- iphone_os64 vulnerabilities
- ipad_os53 vulnerabilities
- Multiple Products53 vulnerabilities
- Security Update - Catalina43 vulnerabilities
- Xcode43 vulnerabilities
- iCloud for Windows (Microsoft Store)22 vulnerabilities
- mac_os14 vulnerabilities
- iOS, iPadOS, and macOS11 vulnerabilities
- ios_and_ipados11 vulnerabilities
- MacOS X10 vulnerabilities
- AirPort Base Station Firmware Update7 vulnerabilities
- Apple Music for Android7 vulnerabilities
- itunes5 vulnerabilities
- GarageBand4 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-65400HIGH | Apple macos Improper AuthenticationAn authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials. CWE-287Aug 6, 2026 | CVSS7.1v3.1 | EPSS0.304% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-43757CRITICAL | Generated title:Apple macOS Out-of-Bounds Read VulnerabilityAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination. CWE-125Jul 27, 2026 | CVSS9.8v3.1 | EPSS0.327% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64737HIGH | Generated title:Apple macOS Sandbox Breakout via Authorization IssueAn authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox. CWE-284Jul 27, 2026 | CVSS8.2v3.1 | EPSS0.115% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-43782MEDIUM | Generated title:macOS Sensitive User Data Access VulnerabilityThis issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access sensitive user data. CWE-200Jul 27, 2026 | CVSS5.5v3.1 | EPSS0.121% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-43805CRITICAL | Generated title:Apple iOS, iPadOS, macOS, and watchOS Race Condition Leading to Kernel Memory Write or System TerminationA race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory. CWE-362Jul 27, 2026 | CVSS9.8v3.1 | EPSS0.27% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-39873CRITICAL | Generated title:Apple macOS SMB Server Connection Memory Corruption Denial of ServiceThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Connecting to a malicious SMB server may lead to unexpected system termination. CWE-119Jul 27, 2026 | CVSS9.8v3.1 | EPSS0.327% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64776MEDIUM | Generated title:Apple macOS Out-of-Bounds Read Kernel Memory DisclosureThe issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to disclose kernel memory. CWE-125Jul 27, 2026 | CVSS5.5v3.1 | EPSS0.122% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-43813HIGH | Generated title:Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS Code Signing Bypass VulnerabilityA validation issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A maliciously crafted app may be able to bypass code signing enforcement. CWE-20Jul 27, 2026 | CVSS7.1v3.1 | EPSS0.129% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64721MEDIUM | Generated title:Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS Sensitive User Data Access VulnerabilityThis issue was addressed through improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data. CWE-664Jul 27, 2026 | CVSS5.5v3.1 | EPSS0.129% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20672MEDIUM | Generated title:Apple macOS Information DisclosureAn information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to access sensitive user data. CWE-200Jul 27, 2026 | CVSS5.5v3.1 | EPSS0.121% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64740CRITICAL | Generated title:Apple iOS, iPadOS, macOS, and tvOS Path Traversal VulnerabilityA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6. A malicious app may be able to break out of its sandbox. CWE-22Jul 27, 2026 | CVSS9.3v3.1 | EPSS0.165% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64691CRITICAL | Generated title:Apple macOS Buffer OverflowA buffer overflow was addressed with improved size validation. This issue is fixed in macOS Tahoe 26.6. An app may be able to cause unexpected system termination. CWE-120Jul 27, 2026 | CVSS9.8v3.1 | EPSS0.343% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-43673HIGH | Generated title:Apple Multiple Operating Systems Memory Corruption VulnerabilityThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted audio file may corrupt process memory. CWE-119Jul 27, 2026 | CVSS7.8v3.1 | EPSS0.124% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64783HIGH | Generated title:Apple Safari, iOS, iPadOS, macOS, visionOS, and watchOS Use-After-Free VulnerabilityA use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash. CWE-416Jul 27, 2026 | CVSS8.8v3.1 | EPSS0.208% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-43809CRITICAL | Generated title:Apple macOS Out-of-Bounds Read VulnerabilityAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination. CWE-125Jul 27, 2026 | CVSS9.8v3.1 | EPSS0.417% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-43665MEDIUM | Generated title:macOS Screen Sharing Legacy VNC Password Information DisclosureThis issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A local attacker may be able to determine the legacy VNC password configured for Screen Sharing. CWE-862Jul 27, 2026 | CVSS5.5v3.1 | EPSS0.098% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-43777HIGH | Generated title:Apple macOS Remote Denial of Service via Improper Input ValidationThis issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote attacker may be able to cause a denial of service. CWE-20Jul 27, 2026 | CVSS7.5v3.1 | EPSS0.511% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-43799CRITICAL | Generated title:Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS Use-After-Free VulnerabilityA use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination. CWE-416Jul 27, 2026 | CVSS9.8v3.1 | EPSS0.46% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-43776HIGH | Generated title:Apple iOS, iPadOS, and macOS Buffer Overflow VulnerabilityA buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution. CWE-120Jul 27, 2026 | CVSS7.8v3.1 | EPSS0.154% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-28900MEDIUM | Generated title:macOS Gatekeeper Bypass via Malicious ZIP ArchiveA file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A maliciously crafted ZIP archive may bypass Gatekeeper checks. | CVSS5.5v3.1 | EPSS0.106% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-43672HIGH | Generated title:macOS Incorrect Authorization Bypass of Privacy PreferencesAn authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious application may be able to bypass Privacy preferences. CWE-863Jul 27, 2026 | CVSS7.1v3.1 | EPSS0.116% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-43760HIGH | Generated title:macOS Access Control Bypass Leading to Sensitive Data DisclosureAn access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access user-sensitive data. CWE-284Jul 27, 2026 | CVSS8.6v3.1 | EPSS0.24% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64716HIGH | Generated title:Apple Multiple Products Memory Corruption Vulnerability via Malicious ImageThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted image may corrupt process memory. CWE-119Jul 27, 2026 | CVSS7.8v3.1 | EPSS0.133% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-28982CRITICAL | Generated title:macOS Race Condition Leading to Kernel Memory CorruptionA race condition was addressed with improved locking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory. CWE-362Jul 27, 2026 | CVSS9.8v3.1 | EPSS0.322% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64700CRITICAL | Generated title:Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS Use-After-Free VulnerabilityA use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination. CWE-416Jul 27, 2026 | CVSS9.8v3.1 | EPSS0.46% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |