SB2026091501 - Multiple vulnerabilities in macOS Tahoe
Published: September 15, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 153 vulnerabilities.
1) Out-of-bounds write (CVE-ID: CVE-2026-86882)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds write in Accelerate Framework. A remote attacker can trick the victim into opening a specially crafted file and perform unexpected process termination.
2) Exposure of sensitive information to an unauthorized actor (CVE-ID: CVE-2026-43664)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to excessive data output in Accessibility. A local application can access sensitive user data.
3) Improper input validation (CVE-ID: CVE-2026-86910)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to an unspecified flaw in APFS when a local application accesses filesystem data. A local user can exploit the flaw to gain access to sensitive information.
4) Out-of-bounds write (CVE-ID: CVE-2026-84523)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to an out-of-bounds write in APFS. A local application can cause unexpected system termination or write kernel memory.
5) Permissions, privileges, and access controls (CVE-ID: CVE-2026-86888)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improperly imposed security restrictions in App Store. A local application can read a persistent account identifier.
6) Permissions, privileges, and access controls (CVE-ID: CVE-2026-84587)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improperly imposed security restrictions in AppKit. A local application can access protected user data.
7) State issues (CVE-ID: CVE-2026-20683)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a state management issue in Apple Account. A local application can use the Sign In With Apple authentication flow to access the user\'s Apple Account.
8) Improper input validation (CVE-ID: CVE-2026-65408)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation in Apple Neural Engine. A local application can cause unexpected system termination.
9) Use after free (CVE-ID: CVE-2026-65407)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a use-after-free error in AppleAVD. A local application can cause unexpected system termination.
10) Out-of-bounds write (CVE-ID: CVE-2026-84519)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds write in AppleDouble. A remote attacker can trick the victim into opening a specially crafted file and perform unexpected system termination.
11) Improper input validation (CVE-ID: CVE-2026-65381)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to insufficient input validation in AppleMobileFileIntegrity. A local application can break out of its sandbox.
12) Improper input validation (CVE-ID: CVE-2026-43763)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to insufficient input validation in ATS. A local application can trick the victim into opening a specially crafted file and read files outside of its sandbox.
13) Information exposure through log files (CVE-ID: CVE-2026-84525)
CWE-ID: CWE-532 - Information Exposure Through Log Files
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to inclusion of sensitive information into a log file in ATS. A local application can access user-sensitive data.
14) Improper input validation (CVE-ID: CVE-2026-65342)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to insufficient input validation in ATS. A local application can access sensitive user data.
15) Permissions, privileges, and access controls (CVE-ID: CVE-2026-84583)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improperly imposed security restrictions in AuthKit. A local application can read a persistent account identifier.
16) Improper input validation (CVE-ID: CVE-2026-84568)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an unspecified flaw in autofs when it is used. A local user can exploit the vulnerability to escalate privileges on the system.
17) Improper access control (CVE-ID: CVE-2026-84570)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improper access restrictions in autofs. A local application can bypass Gatekeeper checks.
18) State issues (CVE-ID: CVE-2026-84535)
CWE-ID: CWE-371 - State Issues
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a state management issue in Automator. A local application can break out of its sandbox.
19) Improper access control (CVE-ID: CVE-2026-65410)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to improper access restrictions in AVEVideoEncoder. A local application can cause unexpected system termination.
20) Memory corruption (CVE-ID: CVE-2026-84616)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in AVEVideoEncoder. A local application can cause unexpected system termination.
21) State issues (CVE-ID: CVE-2026-84607)
CWE-ID: CWE-371 - State Issues
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a state management issue in AVEVideoEncoder. A local application can execute arbitrary code with kernel privileges.
22) Improper input validation (CVE-ID: CVE-2026-65406)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to insufficient input validation in BackgroundAssets. A local application can access sensitive user data.
23) Out-of-bounds write (CVE-ID: CVE-2026-65414)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds write in Bluetooth. A remote attacker can trick the victim into opening a specially crafted file and cause unexpected app termination or arbitrary code execution.
24) Memory corruption (CVE-ID: CVE-2026-84567)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in cd9660. A local application can cause unexpected system termination.
25) Protection mechanism failure (CVE-ID: CVE-2026-65399)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to insufficient implementation of security measures in copyfile when copying data from an archive. A local user can bypass a file quarantine and bypass implemented security restrictions.
26) State issues (CVE-ID: CVE-2026-86891)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a state management issue in Core Bluetooth. A local application can access Bluetooth device information.
27) Memory corruption (CVE-ID: CVE-2026-43683)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in CoreDrag. A local application can cause unexpected process termination or disclose process memory.
28) Improper access control (CVE-ID: CVE-2026-43789)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improper access restrictions in CoreMedia. A local application can access user-sensitive data.
29) Out-of-bounds write (CVE-ID: CVE-2026-65344)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds write in CoreMedia. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.
30) Out-of-bounds write (CVE-ID: CVE-2026-86876)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to an out-of-bounds write in CoreMedia when processing media content. A local user can trigger the out-of-bounds write to bypass implemented security restrictions.
31) Memory corruption (CVE-ID: CVE-2026-43702)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a boundary error in CoreMedia Video Toolbox. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination or corrupt process memory.
32) Improper input validation (CVE-ID: CVE-2026-84624)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an unspecified flaw in CoreML when a local application interacts with the component. A local user can use a local application to escalate privileges on the system.
33) Improper input validation (CVE-ID: CVE-2026-43737)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to insufficient input validation in CoreMotion. A local application can access motion data from headphones without user consent.
34) Protection mechanism failure (CVE-ID: CVE-2026-84574)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to bypass privacy preferences.
The vulnerability exists due to insufficient implementation of security measures in CoreServices. A local application can bypass privacy preferences.
35) Improper access control (CVE-ID: CVE-2026-28899)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improper access restrictions in CoreServices. A local application can gain access to sensitive information.
36) Improper input validation (CVE-ID: CVE-2026-84559)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to insufficient input validation in CoreServices. A local application can trick the victim into opening a specially crafted file and access restricted files.
37) Improper access control (CVE-ID: CVE-2026-43786)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to improper access restrictions in CoreServices. A local application can gain root privileges.
38) Improper input validation (CVE-ID: CVE-2026-65412)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation in CoreText. A remote attacker can trick the victim into opening a specially crafted file and perform a denial-of-service.
39) Out-of-bounds write (CVE-ID: CVE-2026-84575)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds write in CoreUI. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.
40) Out-of-bounds write (CVE-ID: CVE-2026-84511)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds write in CoreUI. A remote attacker can trick the victim into opening a specially crafted file and perform unexpected process termination.
41) Improper access control (CVE-ID: CVE-2026-84563)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to improper access restrictions in CUPS. A local application can cause unexpected system termination.
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to incorrect handling of path names in CUPS. A local application can gain elevated privileges.
43) Improper input validation (CVE-ID: CVE-2026-43692)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an unspecified flaw in CUPS when interacting with CUPS from a local application. A local user can execute a local application to cause a denial of service.
44) Improper input validation (CVE-ID: CVE-2026-84554)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in CUPS when processing input. A remote attacker can provide crafted input to cause a denial of service.
45) State issues (CVE-ID: CVE-2026-84540)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a state management issue in CUPS. A local application can access sensitive user data.
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to incorrect handling of path names in CUPS. A local application can gain root privileges.
47) Memory corruption (CVE-ID: CVE-2026-84516)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in CUPS. A local application can trick the victim into opening a specially crafted file and perform a denial of service (DoS) attack.
48) Improper input validation (CVE-ID: CVE-2026-43698)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to insufficient input validation in CUPS. A local application can gain root privileges.
49) Improper input validation (CVE-ID: CVE-2026-84541)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to insufficient input validation in CUPS. A local application can trick the victim into opening a specially crafted file and access restricted files.
50) Information disclosure (CVE-ID: CVE-2026-84612)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to an unspecified flaw in DeviceCheck when used by a local application. A local user can use a local application to gain access to sensitive information.
51) Out-of-bounds write (CVE-ID: CVE-2026-84505)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to an out-of-bounds write in Directory Utility. A local application can gain root privileges.
52) Memory corruption (CVE-ID: CVE-2026-84552)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in Disk Images. A local application can cause unexpected system termination.
53) Memory corruption (CVE-ID: CVE-2026-84565)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in Disk Images. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.
54) Improper input validation (CVE-ID: CVE-2026-84550)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service (DoS).
The vulnerability exists due to an unspecified flaw in Disk Images when a local application interacts with Disk Images. A local user can use a local application to cause a denial of service (DoS).
55) Improper access control (CVE-ID: CVE-2026-65362)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to improper access restrictions in Disk Images. A local application can gain root privileges.
56) Memory corruption (CVE-ID: CVE-2026-84512)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper restriction of operations within the bounds of a memory buffer in Disk Images when processing disk images. A local user can cause the vulnerable component to process a disk image to escalate privileges on the system.
57) Memory corruption (CVE-ID: CVE-2026-84510)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 2.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper restriction of operations within the bounds of a memory buffer in exFAT when processing exFAT file systems. A remote attacker can trigger the vulnerability to cause a denial of service.
58) Permissions, privileges, and access controls (CVE-ID: CVE-2026-43785)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to improperly imposed security restrictions in File Bookmark. A local application can trick the victim into opening a specially crafted file and modify a file it only had permission to read.
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to incorrect handling of path names in file_cmds. A remote attacker can trick the victim into opening a specially crafted file and escalate privileges on the system.
60) Memory corruption (CVE-ID: CVE-2026-84524)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in FontParser. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.
61) Memory corruption (CVE-ID: CVE-2026-65409)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in Foundation. A local application can cause a denial of service.
62) Improper input validation (CVE-ID: CVE-2026-84618)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to insufficient input validation in Game Center. A local application can access sensitive user data.
63) State issues (CVE-ID: CVE-2026-84492)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a state management issue in Graphics. A local application can cause unexpected system termination.
64) Heap-based buffer overflow (CVE-ID: CVE-2022-3437)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. A remote user can send specially crafted data to the application, trigger a heap-based buffer overflow and perform a denial of service (DoS) attack.
65) Memory corruption (CVE-ID: CVE-2026-28934)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper restriction of operations within the bounds of a memory buffer in HFS when handling HFS filesystem operations. A local user can trigger the flaw through HFS filesystem operations to cause a denial of service.
66) Memory corruption (CVE-ID: CVE-2026-84581)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper restriction of operations within the bounds of a memory buffer in HFS when interacting with the HFS component. A local user can exploit the flaw to escalate privileges on the system.
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to incorrect handling of path names in Image Capture. A local application can access user-sensitive data.
68) Improper input validation (CVE-ID: CVE-2026-84564)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access sensitive information.
The vulnerability exists due to an unspecified flaw in ImageIO when processing input. A remote attacker can cause ImageIO to process input to access sensitive information.
69) Out-of-bounds write (CVE-ID: CVE-2026-65395)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to write data outside of intended memory bounds.
The vulnerability exists due to an out-of-bounds write in ImageIO when processing input. A remote attacker can send specially crafted input to the affected component to write data outside of intended memory bounds.
70) State issues (CVE-ID: CVE-2026-43743)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a state management issue in IOGPUFamily. A local application can cause unexpected system termination.
71) Use after free (CVE-ID: CVE-2026-28969)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a use-after-free error in IOKit. A local application can cause unexpected system termination.
72) Memory corruption (CVE-ID: CVE-2026-84566)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper restriction of operations within the bounds of a memory buffer in the kernel when vulnerable kernel code is executed. A local user can trigger the flaw to escalate privileges on the system.
73) Out-of-bounds write (CVE-ID: CVE-2026-28968)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to an out-of-bounds write in Kernel. A local application can cause unexpected system termination or corrupt kernel memory.
74) Memory corruption (CVE-ID: CVE-2026-84549)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper restriction of operations within bounds of a memory buffer in the kernel when performing affected kernel operations. A local user can trigger the vulnerability to escalate privileges on the system.
75) Out-of-bounds write (CVE-ID: CVE-2026-84619)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to an out-of-bounds write in Kernel. A local application can cause unexpected system termination or write kernel memory.
76) Memory corruption (CVE-ID: CVE-2026-43790)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to a boundary error in Kernel. A remote attacker can trick the victim into opening a specially crafted file and cause unexpected system termination or corrupt kernel memory.
77) Memory corruption (CVE-ID: CVE-2026-84622)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a boundary error in Kernel. A local application can read uninitialized kernel memory.
78) Memory corruption (CVE-ID: CVE-2026-65377)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in Kernel. A local application can cause unexpected system termination.
79) State issues (CVE-ID: CVE-2026-65369)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a state management issue in Kernel. A local application can gain access to sensitive information.
80) Improper input validation (CVE-ID: CVE-2026-84544)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper input validation in the kernel when handling input. A local user can provide crafted input to escalate privileges on the system.
81) Memory corruption (CVE-ID: CVE-2026-43687)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper restriction of operations within the bounds of a memory buffer in the kernel when processing input. A local user can interact with the kernel to disclose sensitive information.
82) Permissions, privileges, and access controls (CVE-ID: CVE-2026-86917)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to improperly imposed security restrictions in Kernel. A local application can gain root privileges.
83) Use-after-free (CVE-ID: CVE-2026-43686)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error in OS kernel when handling responses from an NFS server. A remote attacker can trick the victim into connecting to a malicious NFS server, trigger a use-after-free error and execute arbitrary code on the system.
84) Improper input validation (CVE-ID: CVE-2026-84538)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation in Kernel. A remote attacker can trick the victim into opening a specially crafted file and cause a denial-of-service.
85) Memory corruption (CVE-ID: CVE-2026-65364)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in Kernel. A remote attacker can trick the victim into opening a specially crafted file and cause unexpected system termination.
86) Improper initialization (CVE-ID: CVE-2026-65405)
CWE-ID: CWE-665 - Improper Initialization
CVSSv4: 6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improper initialization within the OS kernel. A local local application can determine kernel memory layout.
87) State issues (CVE-ID: CVE-2026-84630)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a state management issue in Kernel. A local application can cause unexpected system termination.
88) State issues (CVE-ID: CVE-2026-65360)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a state management issue in Kernel. A local application can cause unexpected system termination.
89) State issues (CVE-ID: CVE-2026-65358)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a state management issue in Kernel. A local application can cause unexpected system termination.
90) State issues (CVE-ID: CVE-2026-65401)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a state management issue in Kernel. A local application can cause unexpected system termination.
91) Improper input validation (CVE-ID: CVE-2026-84530)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to an unspecified flaw in the kernel when a local application interacts with it. A local user can use a local application to gain access to sensitive information.
92) Improper access control (CVE-ID: CVE-2026-84602)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to improper access restrictions in Kernel. A local application can cause unexpected system termination.
93) Use after free (CVE-ID: CVE-2026-65402)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a use-after-free error in Kernel. A local application can cause unexpected system termination.
94) Use after free (CVE-ID: CVE-2026-84521)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a use-after-free error in Kernel. A local application can cause unexpected system termination.
95) State issues (CVE-ID: CVE-2026-84507)
CWE-ID: CWE-371 - State Issues
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a state management issue in Kernel. A local application can cause unexpected system termination or corrupt kernel memory.
96) Improper input validation (CVE-ID: CVE-2026-84517)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation in Kernel. A local application can cause unexpected system termination.
97) Improper input validation (CVE-ID: CVE-2026-84561)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an unspecified flaw in the kernel when executing a local application. A local user can execute a local application to escalate privileges on the system.
98) Memory corruption (CVE-ID: CVE-2026-65359)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in Kernel. A local user can cause unexpected system termination or read kernel memory.
99) Improper access control (CVE-ID: CVE-2026-84514)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to improper access restrictions in Kext Management. A local application can modify protected parts of the file system.
100) Improper input validation (CVE-ID: CVE-2026-84556)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to an unspecified flaw in Keychain Access when a local application interacts with it. A local user can use a local application to interact with Keychain Access to gain access to sensitive information.
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to incorrect handling of path names in LaunchServices. A local application can trick the victim into opening a specially crafted file and access sensitive user data.
102) Improper access control (CVE-ID: CVE-2026-84577)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to bypass implemneted security restrictions.
The vulnerability exists due to improper access restrictions in libxpc. A local application can bypass sandbox restrictions.
103) Improper access control (CVE-ID: CVE-2026-84573)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improper access restrictions in Mail. A local application can access sensitive user data.
104) Information disclosure (CVE-ID: CVE-2026-43787)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a logic issue in Mail. A remote attacker with access to the local network can send a specially crafted email to the victim and obtain sensitive user information.
105) State issues (CVE-ID: CVE-2026-43741)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a state management issue in Messages. A local application can access protected user data.
106) Improper input validation (CVE-ID: CVE-2026-86924)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in MobileAccessoryUpdater when processing input. A local user can provide crafted input to cause a denial of service.
107) Improper input validation (CVE-ID: CVE-2026-84497)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an unspecified flaw in Model I/O when handling remote input. A remote attacker can interact with the vulnerable component remotely to cause a denial of service.
108) Information disclosure (CVE-ID: CVE-2026-84626)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in NetworkExtension. A local application can identify, which other applications were installed by the user.
109) State issues (CVE-ID: CVE-2026-43695)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a state management issue in NetworkExtension. A local application can access sensitive user data.
110) Improper access control (CVE-ID: CVE-2026-64712)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to improper access restrictions in odproxyd. A local application can gain root privileges.
111) Improper access control (CVE-ID: CVE-2026-84580)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to improper access restrictions in quarantine. A local application can break out of its sandbox.
112) Improper access control (CVE-ID: CVE-2026-84578)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to improper access restrictions in quarantine. A local application can break out of its sandbox.
113) Improper access control (CVE-ID: CVE-2026-84576)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improper access restrictions in QuartzCore. A local application can access sensitive user data.
114) Improper input validation (CVE-ID: CVE-2026-84548)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient input validation in Quick Look. A remote attacker can trick the victim into opening a specially crafted file and perform an out-of-bounds read.
115) Improper input validation (CVE-ID: CVE-2026-84532)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation in RealityKit. A remote attacker can trick the victim into opening a specially crafted file and perform a denial of service (DoS) attack.
116) Out-of-bounds write (CVE-ID: CVE-2026-28966)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds write in RealityKit. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.
117) Improper access control (CVE-ID: CVE-2026-65403)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improper access restrictions in Reminders. A local application can access sensitive user data.
118) Improper input validation (CVE-ID: CVE-2026-84487)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient input validation in SceneKit. A remote attacker can trick the victim into opening a specially crafted file and gain access to sensitive information.
119) Improper input validation (CVE-ID: CVE-2026-65413)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation in SceneKit. A local application can cause a denial of service.
120) Out-of-bounds write (CVE-ID: CVE-2026-84546)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in SceneKit when processing remote input. A remote attacker can provide crafted input to cause memory corruption.
121) Out-of-bounds write (CVE-ID: CVE-2026-84611)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause an out-of-bounds write.
The vulnerability exists due to an out-of-bounds write in SceneKit when processing remote input. A remote attacker can provide input to the affected component to cause an out-of-bounds write.
122) Buffer overflow (CVE-ID: CVE-2026-84632)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in SceneKit when processing 3D models. A remote attacker can trick the victim into opening a specially crafted file, trigger memory corruption and execute arbitrary code on the target system.
123) Integer overflow (CVE-ID: CVE-2026-84620)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in SceneKit when processing 3D models. A remote attacker can trick the victim into opening a specially crafted file, trigger an integer overflow and execute arbitrary code on the target system.
124) Memory corruption (CVE-ID: CVE-2026-43697)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to a boundary error in SceneKit. A remote attacker can trick the victim into opening a specially crafted file and perform an out-of-bounds read.
125) Out-of-bounds write (CVE-ID: CVE-2026-84526)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds write in SceneKit. A remote attacker can trick the victim into opening a specially crafted file and perform unexpected process termination.
126) Improper access control (CVE-ID: CVE-2026-43760)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper access control in screen sharing server when handling requests from a local application. A local user can access sensitive information to disclose sensitive information.
127) Improper authentication (CVE-ID: CVE-2026-65400) Exploited
CWE-ID: CWE-287 - Improper Authentication
CVSSv4: 8.6 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authentication.
The vulnerability exists due to improper authentication in Screen Sharing when handling network authentication attempts. A remote attacker can send crafted authentication requests to bypass authentication.
128) Improper certificate validation (CVE-ID: CVE-2026-86889)
CWE-ID: CWE-295 - Improper Certificate Validation
CVSSv4: 8.6 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to improper certificate validation in Security component. A remote attacker on the local network can intercept network traffic.
129) Improper certificate validation (CVE-ID: CVE-2026-86881)
CWE-ID: CWE-295 - Improper Certificate Validation
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to improper certificate validation in Security component. A remote attacker with a compromised intermediate certificate authority can issue certificates with arbitrary extended key usages.
130) Use-after-free (CVE-ID: CVE-2026-43719)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in SMB when handling SMB requests. A remote attacker can send SMB requests to cause a denial of service.
131) Memory corruption (CVE-ID: CVE-2026-84543)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper restriction of operations within the bounds of a memory buffer in SMB when handling SMB operations. A local user can exploit the flaw to escalate privileges on the system.
132) Improper input validation (CVE-ID: CVE-2026-43690)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an unspecified flaw in SMB when accessing the system locally. A local user can exploit the vulnerability to disclose sensitive information.
133) Memory corruption (CVE-ID: CVE-2026-65376)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in SMB. A local application can cause unexpected system termination.
134) Improper input validation (CVE-ID: CVE-2026-84536)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in SMB when handling SMB requests. A remote attacker can send a specially crafted SMB request to cause a denial of service.
135) Memory corruption (CVE-ID: CVE-2026-84537)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a boundary error in SMB. A local application can cause unexpected system termination or corrupt kernel memory.
136) Memory corruption (CVE-ID: CVE-2026-65365)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an unspecified flaw in SMB when handling SMB requests. A remote attacker can send an SMB request to disclose sensitive information.
137) Out-of-bounds write (CVE-ID: CVE-2026-84515)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input in SMB server. A remote attacker can trick the victim into connecting to a malicious SBM server, trigger an out-of-bounds write and execute arbitrary code on the target system.
138) Memory corruption (CVE-ID: CVE-2026-84509)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper restriction of operations within the bounds of a memory buffer in SMB when handling SMB requests. A remote attacker can send a specially crafted SMB request to cause a denial of service.
139) Improper input validation (CVE-ID: CVE-2026-84553)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation in smbx. A remote attacker can trick the victim into opening a specially crafted file and cause a denial-of-service.
140) Improper input validation (CVE-ID: CVE-2026-84609)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an unspecified flaw in Software Update when a local application interacts with it. A local user can exploit the flaw to escalate privileges on the system.
141) Improper access control (CVE-ID: CVE-2026-65361)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improper access restrictions in SoftwareUpdate. A local application can access sensitive user data.
142) State issues (CVE-ID: CVE-2026-65378)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a state management issue in Spotlight. A local application can access sensitive user data.
143) Information disclosure (CVE-ID: CVE-2026-84621)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an unspecified flaw in Spotlight when used by a local application. A local user can exploit the flaw to disclose sensitive information.
144) Permissions, privileges, and access controls (CVE-ID: CVE-2026-65345)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improperly imposed security restrictions in Storage. A local application can access user-sensitive data.
145) Permissions, privileges, and access controls (CVE-ID: CVE-2026-65348)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to improperly imposed security restrictions in Storage. A local application can modify protected parts of the file system.
146) Information disclosure (CVE-ID: CVE-2026-43791)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to an unspecified flaw in StorageKit when used by a local application. A local user can use a local application to gain access to sensitive information.
147) Inclusion of Sensitive Information in Log Files (CVE-ID: CVE-2026-84513)
CWE-ID: CWE-532 - Information Exposure Through Log Files
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to insertion of sensitive information into log files in the Symptom Framework when used by a local application. A local user can use a local application to disclose sensitive information.
148) Information exposure through log files (CVE-ID: CVE-2026-84527)
CWE-ID: CWE-532 - Information Exposure Through Log Files
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to inclusion of sensitive information into a log file in TCC. A local application can access sensitive user data.
149) Memory corruption (CVE-ID: CVE-2026-84572)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in udf. A local application can cause unexpected system termination or read kernel memory.
150) Use after free (CVE-ID: CVE-2026-84506)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a use-after-free error in udf. A local application can execute arbitrary code with kernel privileges.
151) Out-of-bounds write (CVE-ID: CVE-2026-43677)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds write in WebDAV. A local application can perform unexpected app termination.
152) Buffer overflow (CVE-ID: CVE-2026-65374)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when processing WebDav responses. A remote attacker can trick the victim into connecting to a malicious WebDav server, trigger memory corruption and execute arbitrary code on the target system.
153) State issues (CVE-ID: CVE-2026-84617)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a state management issue in XPC. A local application can access sensitive user data.
Remediation
Install update from vendor's website.