SB2026081774 - Multiple vulnerabilities in macOS Sonoma



SB2026081774 - Multiple vulnerabilities in macOS Sonoma

Published: August 17, 2026

Security Bulletin ID SB2026081774
CSH Severity
High
Patch available
YES
Number of vulnerabilities 127
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 2% Medium 13% Low 85%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 127 vulnerabilities.


1) Use after free (CVE-ID: CVE-2026-43778)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a use-after-free error in Kernel. A local application can cause unexpected system termination or corrupt kernel memory.


2) State issues (CVE-ID: CVE-2026-64721)

CWE-ID: CWE-371 - State Issues

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a state management issue in Kernel. A local application can access sensitive user data.


3) Memory corruption (CVE-ID: CVE-2026-28911)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a boundary error in Metal. A local application can corrupt memory of a system process.


4) Improper limitation of a pathname to a restricted directory ('path traversal') (CVE-ID: CVE-2026-43723)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to incorrect handling of path names in MediaRemote. A local application can gain root privileges.


5) Memory corruption (CVE-ID: CVE-2026-64724)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker on the local network to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in mDNSResponder. A remote attacker on the local network can cause a denial-of-service.


6) Permissions, privileges, and access controls (CVE-ID: CVE-2026-64738)

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to improperly imposed security restrictions in Maps. A local application can break out of its sandbox.


7) State issues (CVE-ID: CVE-2026-43766)

CWE-ID: CWE-371 - State Issues

CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to the system to gain access to sensitive information.

The vulnerability exists due to a state management issue in LoginWindow. An attacker with physical access to the system can view sensitive user information.


8) Improper input validation (CVE-ID: CVE-2026-43706)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in libxslt when parsing input. A remote attacker can send specially crafted input to cause a denial of service.


9) Memory corruption (CVE-ID: CVE-2026-43703)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in libxslt. A remote attacker can trick the victim into opening a specially crafted file and perform an unexpected process crash.


10) Out-of-bounds write (CVE-ID: CVE-2026-64739)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to out-of-bounds write in libnotify when processing input. A local user can trigger the vulnerable behavior to cause a denial of service.


11) Improper input validation (CVE-ID: CVE-2026-28973)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to insufficient input validation in libc. A local application can break out of its sandbox.


12) Improper access control (CVE-ID: CVE-2026-28900)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in libarchive when parsing input. A remote attacker can supply crafted input to disclose sensitive information.


13) Improper input validation (CVE-ID: CVE-2026-4424)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper input validation in libarchive when parsing input. A remote attacker can supply specially crafted archive data to disclose sensitive information.


14) Improper access control (CVE-ID: CVE-2026-28983)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper access restrictions in LaunchServices. A remote attacker can trick the victim into opening a specially crafted file and cause a denial of service.


15) Improper access control (CVE-ID: CVE-2026-20672)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper access control in LaunchServices when handling a local application. A local user can leverage a local application to disclose sensitive information.


16) Memory corruption (CVE-ID: CVE-2026-64709)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a boundary error in Kernel. A local application can disclose kernel memory.


17) Improper input validation (CVE-ID: CVE-2026-64774)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation in Model I/O. A remote attacker can trick the victim into opening a specially crafted file and cause unexpected application termination or heap corruption.


18) Improper input validation (CVE-ID: CVE-2026-39868)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to insufficient input validation in Kernel. A local application can cause unexpected system termination or corrupt kernel memory.


19) Improper access control (CVE-ID: CVE-2026-64723)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper access restrictions in Kernel. A local application can access sensitive user data.


20) Information disclosure (CVE-ID: CVE-2026-43754)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper exposure of sensitive information in kernel when running a local application. A local user can execute a local application to disclose sensitive information.


21) Improper input validation (CVE-ID: CVE-2026-43769)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation in Kernel. A local application can cause unexpected system termination.


22) Memory corruption (CVE-ID: CVE-2026-43757)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in Kernel. A local application can cause unexpected system termination.


23) Memory corruption (CVE-ID: CVE-2026-43809)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in Kernel. A local application can cause unexpected system termination.


24) Information disclosure (CVE-ID: CVE-2026-43722)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to potentially sensitive information.

The vulnerability exists due to improper input validation within the OS kernel. A local application can gain access to sensitive kernel state.


25) Improper access control (CVE-ID: CVE-2026-43724)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to improper access control in kernel when handling input from a local application. A local user can run a local application to escalate privileges.


26) Memory corruption (CVE-ID: CVE-2026-43810)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary error in Kernel. A local user can trick the victim into opening a specially crafted file and cause unexpected system termination or corrupt kernel memory.


27) Use after free (CVE-ID: CVE-2026-43799)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a use-after-free error in Kernel. A local application can cause unexpected system termination.


28) Use after free (CVE-ID: CVE-2026-64700)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a use-after-free error in Kernel. A local application can cause unexpected system termination.


29) Use after free (CVE-ID: CVE-2026-43822)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a use-after-free error in Kernel. A local application can cause unexpected system termination.


30) State Issues (CVE-ID: CVE-2026-64735)

CWE-ID: CWE-371 - State Issues

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper handling of behavioral workflow in Kernel when handling requests. A remote attacker can send a specially crafted request to cause a denial of service.


31) Memory corruption (CVE-ID: CVE-2026-43807)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to cause a denial of service.

The vulnerability exists due to memory corruption in MobileAccessoryUpdater when handling input. A local attacker can trigger the vulnerable condition to cause a denial of service.


32) Out-of-bounds write (CVE-ID: CVE-2026-64770)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds write in Model I/O. A remote attacker can trick the victim into opening a specially crafted file and cause unexpected application termination or heap corruption.


33) Improper access control (CVE-ID: CVE-2026-28982)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to improper access control in kernel when handling local operations. A local user can trigger the flaw to escalate privileges.


34) Improper input validation (CVE-ID: CVE-2026-43777)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation in Screen Sharing Server. A remote attacker can trick the victim into opening a specially crafted file and cause a denial of service.


35) State issues (CVE-ID: CVE-2026-28932)

CWE-ID: CWE-371 - State Issues

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a state management issue in xar. A local application can cause a denial of service.


36) Memory corruption (CVE-ID: CVE-2026-43750)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a boundary error in Wi‑Fi. A local application can execute arbitrary code out of its sandbox or with certain elevated privileges.


37) Memory corruption (CVE-ID: CVE-2026-64699)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a boundary error in WebDAV. A local application can disclose kernel memory.


38) Use after free (CVE-ID: CVE-2026-64703)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a use-after-free error in WebDAV. A local application can cause a denial-of-service.


39) Memory corruption (CVE-ID: CVE-2026-43768)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in udf. A local application can cause unexpected system termination.


40) Improper access control (CVE-ID: CVE-2026-43770)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper access control in StorageKit when handling local application access. A local user can access sensitive information to disclose sensitive information.


41) Memory corruption (CVE-ID: CVE-2026-43774)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a boundary error in Spotlight. A local application can access sensitive user data.


42) Memory corruption (CVE-ID: CVE-2026-64704)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in SMB. A local application can cause unexpected system termination.


43) Memory corruption (CVE-ID: CVE-2026-64696)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary error in SMB. A local user can trick the victim into opening a specially crafted file and cause unexpected system termination or corrupt kernel memory.


44) Memory corruption (CVE-ID: CVE-2026-39873)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to memory corruption in SMB when handling requests. A remote attacker can send a specially crafted request to cause a denial of service.


45) State issues (CVE-ID: CVE-2026-43755)

CWE-ID: CWE-371 - State Issues

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a state management issue in SecurityAgent. A local application can gain root privileges.


46) Improper access control (CVE-ID: CVE-2026-43760)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper access control in screen sharing server when handling requests from a local application. A local user can access sensitive information to disclose sensitive information.


47) Information disclosure (CVE-ID: CVE-2026-43665)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to gain access to sensitive information. 

The vulnerability exists due to improper access restrictions in the Screen Sharing Server. A local user can determine the legacy VNC password configured for Screen Sharing.


48) Improper access control (CVE-ID: CVE-2026-43779)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to gain unauthorized access.

The vulnerability exists due to improper access control in Screen Sharing Server when handling requests from a local application. A local user can interact with the vulnerable component to gain unauthorized access.


49) Out-of-bounds write (CVE-ID: CVE-2026-64769)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds write in Model I/O. A remote attacker can trick the victim into opening a specially crafted file and cause unexpected application termination or heap corruption.


50) Improper input validation (CVE-ID: CVE-2026-64765)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation in SceneKit. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination or arbitrary code execution.


51) Improper input validation (CVE-ID: CVE-2026-64766)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation in SceneKit. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination or arbitrary code execution.


52) Out-of-bounds write (CVE-ID: CVE-2026-64763)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds write in SceneKit. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination or arbitrary code execution.


53) Out-of-bounds write (CVE-ID: CVE-2026-64764)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error in SceneKit. A remote attacker can create a specially crafted file, trick the victim into opening it using the affected software, trigger an out-of-bounds write and execute arbitrary code on the target system.


54) Permissions, privileges, and access controls (CVE-ID: CVE-2026-39874)

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to improperly imposed security restrictions in Remote Management. A local application can gain root privileges.


55) Memory corruption (CVE-ID: CVE-2026-43694)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a boundary error in quarantine. A local application can cause unexpected system termination or write kernel memory.


56) Memory corruption (CVE-ID: CVE-2026-28896)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to memory corruption in ppp when handling input. A local user can trigger the vulnerable component to cause a denial of service.


57) Improper link resolution before file access ('link following') (CVE-ID: CVE-2026-43765)

CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to insecure symbolic link following in PackageKit. A local application can modify protected parts of the file system.


58) Improper access control (CVE-ID: CVE-2026-64711)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to bypass security restrictions.

The vulnerability exists due to improper access control in NSColorPanel when invoked by a local application. A local user can invoke the vulnerable component to bypass security restrictions.


59) Improper access control (CVE-ID: CVE-2026-28961)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to the system to gain access to sensitive information.

The vulnerability exists due to improper access restrictions in Network Extensions. An attacker with physical access to the system can view sensitive user information.


60) Improper input validation (CVE-ID: CVE-2026-43772)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to insufficient input validation in NetFSFramework. A local application can break out of its sandbox.


61) Improper input validation (CVE-ID: CVE-2026-43771)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation in Net-SNMP. A local application can cause a denial-of-service.


62) Improper input validation (CVE-ID: CVE-2026-64768)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation in Model I/O. A local application can trick the victim into opening a specially crafted file and perform a denial of service (DoS) attack.


63) Improper limitation of a pathname to a restricted directory ('path traversal') (CVE-ID: CVE-2026-43749)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to incorrect handling of path names in Accounts. A local application can trick the victim into opening a specially crafted file and gain root privileges.


64) Memory corruption (CVE-ID: CVE-2026-64775)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in Kernel. A local application can cause unexpected system termination.


65) Improper access control (CVE-ID: CVE-2026-28849)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in BOM when handling requests. A remote user can access sensitive information to disclose sensitive information.


66) Permissions, privileges, and access controls (CVE-ID: CVE-2026-39875)

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to improperly imposed security restrictions in CUPS. A local application can gain root privileges.


67) Improper input validation (CVE-ID: CVE-2026-64710)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:/VI:/VA:/SC:N/SI:N/SA:N]



68) Out-of-bounds write (CVE-ID: CVE-2026-43802)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds write in CoreVideo. A local application can cause unexpected system termination.


69) Memory corruption (CVE-ID: CVE-2026-43738)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to a boundary error in CoreUI. A remote attacker can trick the victim into opening a specially crafted file and gain access to sensitive information.


70) Improper access control (CVE-ID: CVE-2026-28936)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to improper access restrictions in CoreServices. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.


71) Memory corruption (CVE-ID: CVE-2026-43711)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in CoreMedia. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.


72) Out-of-bounds write (CVE-ID: CVE-2026-43803)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds write in CoreAudio. A remote attacker can trick the victim into opening a specially crafted file and cause unexpected system termination.


73) Out-of-bounds write (CVE-ID: CVE-2026-43744)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds write in CoreAudio. A remote attacker can trick the victim into opening a specially crafted file and perform a denial of service (DoS) attack.


74) Memory corruption (CVE-ID: CVE-2026-43673)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to a boundary error in CoreAudio. A remote attacker can trick the victim into opening a specially crafted file and escalate privileges on the system.


75) State issues (CVE-ID: CVE-2026-43693)

CWE-ID: CWE-371 - State Issues

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a state management issue in Core Services. A local application can gain root privileges.


76) Improper input validation (CVE-ID: CVE-2026-43756)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to insufficient input validation in Control Center. A local application can access user-sensitive data.


77) Improper access control (CVE-ID: CVE-2026-64734)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass access restrictions.

The vulnerability exists due to improper access control in contacts when handling requests. A remote attacker can send a crafted request to bypass access restrictions.


78) Memory corruption (CVE-ID: CVE-2026-64698)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in cd9660. A local application can cause unexpected system termination or read kernel memory.


79) Improper input validation (CVE-ID: CVE-2026-64707)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise the affected component.

The vulnerability exists due to improper input validation in BackgroundAssets when handling input from a local application. A local user can provide crafted input to compromise the affected component.


80) Authentication Bypass by Primary Weakness (CVE-ID: CVE-2026-3784)

CWE-ID: CWE-305 - Authentication Bypass by Primary Weakness

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to wrong proxy connection reuse with credentials. A remote attacker can bypass authentication and gain access to the target system.


81) Memory corruption (CVE-ID: CVE-2026-64762)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in AVEVideoEncoder. A local application can cause unexpected system termination.


82) Improper access control (CVE-ID: CVE-2026-64747)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to improper access control in AVEVideoEncoder when accessed by a local application. A local user can interact with the vulnerable component to escalate privileges.


83) Out-of-bounds write (CVE-ID: CVE-2026-64725)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds write in Audio. A local application can cause a denial-of-service.


84) Improper access control (CVE-ID: CVE-2026-64702)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to improper access restrictions in Audio. A local application can break out of its sandbox.


85) Improper input validation (CVE-ID: CVE-2026-43763)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to insufficient input validation in ATS. A local application can trick the victim into opening a specially crafted file and read files outside of its sandbox.


86) State Issues (CVE-ID: CVE-2026-43672)

CWE-ID: CWE-371 - State Issues

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to missing release of resource after effective lifetime in Assets when handling local application input. A local user can trigger the vulnerable component to cause a denial of service.


87) Memory corruption (CVE-ID: CVE-2026-43681)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to a boundary error in AppleRAID. A local user can read kernel memory.


88) State issues (CVE-ID: CVE-2026-64737)

CWE-ID: CWE-371 - State Issues

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a state management issue in Apple Account. A local application can break out of its sandbox.


89) State issues (CVE-ID: CVE-2026-43781)

CWE-ID: CWE-371 - State Issues

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a state management issue in Apple Account. A local application can access sensitive user data.


90) Improper access control (CVE-ID: CVE-2026-43801)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper access restrictions in App Store. A local application can access sensitive user data.


91) Memory corruption (CVE-ID: CVE-2026-64695)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary error in APFS. A local user can trick the victim into opening a specially crafted file and cause unexpected system termination or corrupt kernel memory.


92) Double free (CVE-ID: CVE-2026-23918)

CWE-ID: CWE-415 - Double Free

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service and possibly execute arbitrary code.

The vulnerability exists due to a double free in Apache HTTP Server HTTP/2 handling when processing an early reset. A remote attacker can trigger an early reset condition to cause a denial of service and possibly execute arbitrary code.

The issue is specific to the HTTP/2 protocol.


93) Memory corruption (CVE-ID: CVE-2026-64767)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to a boundary error in afpfs. A remote attacker can trick the victim into opening a specially crafted file and cause unexpected system termination or corrupt kernel memory.


94) Improper input validation (CVE-ID: CVE-2026-43698)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to insufficient input validation in CUPS. A local application can gain root privileges.


95) Insufficiently protected credentials (CVE-ID: CVE-2026-3783)

CWE-ID: CWE-522 - Insufficiently Protected Credentials

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information on the system.

The vulnerability exists due to insufficiently protected credentials When the OAuth2 bearer token is used for an HTTP(S) transfer. A remote attacker can gain access to sensitive information on the system.


96) Improper access control (CVE-ID: CVE-2026-64744)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper access control in kernel when handling requests from a local application. A local user can run a local application to disclose sensitive information.


97) Memory corruption (CVE-ID: CVE-2026-43767)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in HFS. A local application can cause unexpected system termination.


98) Improper access control (CVE-ID: CVE-2026-43782)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper access restrictions in Kernel. A local application can access sensitive user data.


99) Memory corruption (CVE-ID: CVE-2026-39877)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a boundary error in IOSkywalkFamily. A local application can disclose kernel memory.


100) State issues (CVE-ID: CVE-2026-43805)

CWE-ID: CWE-371 - State Issues

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a state management issue in IOKit. A local application can cause unexpected system termination or write kernel memory.


101) Improper access control (CVE-ID: CVE-2026-64693)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper access restrictions in ImageIO. A remote attacker can trick the victim into opening a specially crafted file and perform a denial-of-service.


102) Out-of-bounds write (CVE-ID: CVE-2026-64754)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds write in ImageIO. A remote attacker can trick the victim into opening a specially crafted file and perform a denial-of-service.


103) Memory corruption (CVE-ID: CVE-2026-43661)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to a boundary error in ImageIO. A remote attacker can trick the victim into opening a specially crafted file and escalate privileges on the system.


104) Improper input validation (CVE-ID: CVE-2026-43818)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to insufficient input validation in ImageIO. A remote attacker can trick the victim into opening a specially crafted file and perform arbitrary code execution.


105) Improper input validation (CVE-ID: CVE-2026-43780)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation in ImageIO. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.


106) Memory corruption (CVE-ID: CVE-2026-64716)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to a boundary error in ImageIO. A remote attacker can trick the victim into opening a specially crafted file and escalate privileges on the system.


107) Improper access control (CVE-ID: CVE-2025-43325)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper access restrictions in Icons. A local application can access sensitive user data.


108) Memory corruption (CVE-ID: CVE-2026-43710)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to memory corruption in HFS when parsing input. A local user can trigger the flaw to escalate privileges on the system.


109) Improper input validation (CVE-ID: CVE-2026-43764)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation in HFS. A local application can cause unexpected system termination.


110) Memory corruption (CVE-ID: CVE-2026-64697)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a boundary error in HFS. A local application can cause unexpected system termination or corrupt kernel memory.


111) Memory corruption (CVE-ID: CVE-2026-43773)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to memory corruption in HFS when handling filesystem operations. A local user can trigger the flaw to escalate privileges.


112) State issues (CVE-ID: CVE-2026-43758)

CWE-ID: CWE-371 - State Issues

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a state management issue in Data Detectors UI. A local application can access sensitive user data.


113) Memory corruption (CVE-ID: CVE-2026-28981)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to a boundary error in HFS. A remote attacker can trick the victim into opening a specially crafted file and perform arbitrary code execution.


114) Memory corruption (CVE-ID: CVE-2026-43682)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary error in HFS. A local user can trick the victim into opening a specially crafted file and cause unexpected system termination or corrupt kernel memory.


115) Memory corruption (CVE-ID: CVE-2026-64692)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in Heimdal. A local application can cause a denial-of-service.


116) Exposure of sensitive information to an unauthorized actor (CVE-ID: CVE-2026-43796)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to excessive data output in Game Center. A local application can access sensitive user data.


117) Improper limitation of a pathname to a restricted directory ('path traversal') (CVE-ID: CVE-2026-64740)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to incorrect handling of path names in Game Center. A local application can trick the victim into opening a specially crafted file and break out of its sandbox.


118) Improper access control (CVE-ID: CVE-2026-43714)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper access control in Foundation when handling requests from a local application. A local user can invoke the vulnerable functionality to disclose sensitive information.


119) Memory corruption (CVE-ID: CVE-2026-43753)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to the system to gain access to sensitive information.

The vulnerability exists due to a boundary error in DriverKit. An attacker with physical access to the system can view sensitive user information.


120) Improper input validation (CVE-ID: CVE-2026-43793)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation in DriverKit. A local application can cause unexpected system termination.


121) Memory corruption (CVE-ID: CVE-2026-64776)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a boundary error in Disk Images. A local application can disclose kernel memory.


122) Improper access control (CVE-ID: CVE-2026-28945)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to bypass implemneted security restrictions.

The vulnerability exists due to improper access restrictions in Disk Images. A local application can bypass network restrictions.


123) Improper input validation (CVE-ID: CVE-2026-64694)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation in Disk Images. A local application can cause unexpected system termination.


124) Memory corruption (CVE-ID: CVE-2026-43747)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in Disk Images. A local application can trick the victim into opening a specially crafted file and perform an unexpected app termination.


125) State issues (CVE-ID: CVE-2026-28926)

CWE-ID: CWE-371 - State Issues

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a state management issue in Disk Images. A local application can elevate privileges.


126) Improper access control (CVE-ID: CVE-2026-64708)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper access restrictions in DesktopServices. A local application can trick the victim into opening a specially crafted file and gain access to sensitive information.


127) Improper access control (CVE-ID: CVE-2026-28914)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in zip when processing archive contents. A remote attacker can supply a specially crafted archive to disclose sensitive information.


Remediation

Install update from vendor's website.