SB2026091504 - Multiple vulnerabilities in macOS Golden Gate



SB2026091504 - Multiple vulnerabilities in macOS Golden Gate

Published: September 15, 2026

Security Bulletin ID SB2026091504
CSH Severity
High
Patch available
YES
Number of vulnerabilities 210
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 3% Medium 11% Low 85%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 210 vulnerabilities.


1) Out-of-bounds write (CVE-ID: CVE-2026-86882)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds write in Accelerate Framework. A remote attacker can trick the victim into opening a specially crafted file and perform unexpected process termination.


2) Exposure of sensitive information to an unauthorized actor (CVE-ID: CVE-2026-43664)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to excessive data output in Accessibility. A local application can access sensitive user data.


3) Improper authorization (CVE-ID: CVE-2026-65404)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to bypass privacy preferences.

The vulnerability exists due to improper authorization checks in Accounts. A local application can bypass privacy preferences. 


4) Improper input validation (CVE-ID: CVE-2026-86910)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to an unspecified flaw in APFS when a local application accesses filesystem data. A local user can exploit the flaw to gain access to sensitive information.


5) Out-of-bounds write (CVE-ID: CVE-2026-84523)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to an out-of-bounds write in APFS. A local application can cause unexpected system termination or write kernel memory.


6) Permissions, privileges, and access controls (CVE-ID: CVE-2026-86888)

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improperly imposed security restrictions in App Store. A local application can read a persistent account identifier.


7) Permissions, privileges, and access controls (CVE-ID: CVE-2026-84587)

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improperly imposed security restrictions in AppKit. A local application can access protected user data.


8) Information disclosure (CVE-ID: CVE-2026-84586)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to potentially sensitive information.

The vulnerability exists due to a state issue in Apple Accounts. A local application can obtain sensitive user information. 


9) State issues (CVE-ID: CVE-2026-20683)

CWE-ID: CWE-371 - State Issues

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a state management issue in Apple Account. A local application can use the Sign In With Apple authentication flow to access the user\'s Apple Account.


10) Protection mechanism failure (CVE-ID: CVE-2026-84601)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to bypass implemented security restrictions.

The vulnerability exists due to insufficient implementation of security measures in Apple Intelligence. A local application can bypass Apple Intelligence security prompts.


11) Improper input validation (CVE-ID: CVE-2026-65408)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation in Apple Neural Engine. A local application can cause unexpected system termination.


12) Use after free (CVE-ID: CVE-2026-65407)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a use-after-free error in AppleAVD. A local application can cause unexpected system termination.


13) Out-of-bounds write (CVE-ID: CVE-2026-84519)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds write in AppleDouble. A remote attacker can trick the victim into opening a specially crafted file and perform unexpected system termination.


14) Improper privilege management (CVE-ID: CVE-2026-84520)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to an unspecified flaw in AppleFDEKeyStore when interacting with the component. A local user can exploit the flaw to escalate privileges on the system.


15) Improper input validation (CVE-ID: CVE-2026-65381)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to insufficient input validation in AppleMobileFileIntegrity. A local application can break out of its sandbox.


16) Improper link resolution before file access ('link following') (CVE-ID: CVE-2026-84584)

CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to insecure symbolic link following in Archive Utility. A local application can break out of its sandbox.


17) State issues (CVE-ID: CVE-2026-84522)

CWE-ID: CWE-371 - State Issues

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a state management issue in Archive Utility. A local application can access sensitive user data.


18) Information exposure through log files (CVE-ID: CVE-2026-84525)

CWE-ID: CWE-532 - Information Exposure Through Log Files

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to inclusion of sensitive information into a log file in ATS. A local application can access user-sensitive data.


19) Improper input validation (CVE-ID: CVE-2026-65342)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to insufficient input validation in ATS. A local application can access sensitive user data.


20) Improper authorization (CVE-ID: CVE-2026-86905)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to delete credentials from Keychain. 

The vulnerability exists due to missing authorization checks in Authentication Services. A local application can delete credentials stored in Keychain.


21) Permissions, privileges, and access controls (CVE-ID: CVE-2026-84583)

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improperly imposed security restrictions in AuthKit. A local application can read a persistent account identifier.


22) Improper access control (CVE-ID: CVE-2026-84570)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper access restrictions in autofs. A local application can bypass Gatekeeper checks.


23) Improper input validation (CVE-ID: CVE-2026-84568)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to an unspecified flaw in autofs when it is used. A local user can exploit the vulnerability to escalate privileges on the system.


24) State issues (CVE-ID: CVE-2026-84535)

CWE-ID: CWE-371 - State Issues

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a state management issue in Automator. A local application can break out of its sandbox.


25) Improper access control (CVE-ID: CVE-2026-65410)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to improper access restrictions in AVEVideoEncoder. A local application can cause unexpected system termination.


26) Memory corruption (CVE-ID: CVE-2026-84616)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in AVEVideoEncoder. A local application can cause unexpected system termination.


27) State issues (CVE-ID: CVE-2026-84607)

CWE-ID: CWE-371 - State Issues

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a state management issue in AVEVideoEncoder. A local application can execute arbitrary code with kernel privileges.


28) Improper input validation (CVE-ID: CVE-2026-65406)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to insufficient input validation in BackgroundAssets. A local application can access sensitive user data.


29) Out-of-bounds write (CVE-ID: CVE-2026-65414)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds write in Bluetooth. A remote attacker can trick the victim into opening a specially crafted file and cause unexpected app termination or arbitrary code execution.


30) State issues (CVE-ID: CVE-2026-84560)

CWE-ID: CWE-371 - State Issues

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a state management issue in Bluetooth. A local application can Bluetooth.


31) Improper access control (CVE-ID: CVE-2026-84631)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to improper access restrictions in Bluetooth. A local application can gain root privileges.


32) Memory corruption (CVE-ID: CVE-2026-84567)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in cd9660. A local application can cause unexpected system termination.


33) Protection mechanism failure (CVE-ID: CVE-2026-65399)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to bypass implemented security restrictions.

The vulnerability exists due to insufficient implementation of security measures in copyfile when copying data from an archive. A local user can bypass a file quarantine and bypass implemented security restrictions. 


34) State issues (CVE-ID: CVE-2026-86891)

CWE-ID: CWE-371 - State Issues

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a state management issue in Core Bluetooth. A local application can access Bluetooth device information.


35) Memory corruption (CVE-ID: CVE-2026-43683)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in CoreDrag. A local application can cause unexpected process termination or disclose process memory.


36) Improper access control (CVE-ID: CVE-2026-43789)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper access restrictions in CoreMedia. A local application can access user-sensitive data.


37) Improper input validation (CVE-ID: CVE-2026-64752)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to insufficient input validation in CoreMedia. A remote attacker can trick the victim into opening a specially crafted file and perform arbitrary code execution.


38) Out-of-bounds write (CVE-ID: CVE-2026-86876)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to bypass implemented security restrictions.

The vulnerability exists due to an out-of-bounds write in CoreMedia when processing media content. A local user can trigger the out-of-bounds write to bypass implemented security restrictions.


39) Out-of-bounds write (CVE-ID: CVE-2026-65344)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds write in CoreMedia. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.


40) Improper input validation (CVE-ID: CVE-2026-84624)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to an unspecified flaw in CoreML when a local application interacts with the component. A local user can use a local application to escalate privileges on the system.


41) Improper input validation (CVE-ID: CVE-2026-43737)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to insufficient input validation in CoreMotion. A local application can access motion data from headphones without user consent.


42) Protection mechanism failure (CVE-ID: CVE-2026-84574)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to bypass privacy preferences.

The vulnerability exists due to insufficient implementation of security measures in CoreServices. A local application can bypass privacy preferences.


43) Improper input validation (CVE-ID: CVE-2026-84559)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to insufficient input validation in CoreServices. A local application can trick the victim into opening a specially crafted file and access restricted files.


44) Improper access control (CVE-ID: CVE-2026-43786)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to improper access restrictions in CoreServices. A local application can gain root privileges.


45) Improper input validation (CVE-ID: CVE-2026-65412)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation in CoreText. A remote attacker can trick the victim into opening a specially crafted file and perform a denial-of-service.


46) Memory corruption (CVE-ID: CVE-2026-84596)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to a boundary error in CoreText. A remote attacker can trick the victim into opening a specially crafted file and gain access to sensitive information.


47) Out-of-bounds write (CVE-ID: CVE-2026-84575)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds write in CoreUI. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.


48) Memory corruption (CVE-ID: CVE-2026-84489)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in CoreUI. A local application can cause a denial of service.


49) Memory corruption (CVE-ID: CVE-2026-84571)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in CoreUI. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.


50) Memory corruption (CVE-ID: CVE-2026-43738)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to a boundary error in CoreUI. A remote attacker can trick the victim into opening a specially crafted file and gain access to sensitive information.


51) Out-of-bounds write (CVE-ID: CVE-2026-84511)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds write in CoreUI. A remote attacker can trick the victim into opening a specially crafted file and perform unexpected process termination.


52) Improper access control (CVE-ID: CVE-2026-84563)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to improper access restrictions in CUPS. A local application can cause unexpected system termination.


53) Heap-based buffer overflow (CVE-ID: CVE-2026-34979)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the CUPS scheduler when processing IPP job attributes. A remote attacker can send a specially crafted IPP request with large URI attributes to trigger a heap-based buffer overflow in the `get_options()` function, leading to memory corruption and a crash of the `cupsd` service.

The vulnerability specifically arises because the size calculation for the options string uses `ipp_length()`, which excludes URI attributes, but the serialization process still writes URI attributes such as `job-uuid` and `job-authorization-uri` without bounds checking.


54) Improper input validation (CVE-ID: CVE-2026-43698)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to insufficient input validation in CUPS. A local application can gain root privileges.


55) Improper limitation of a pathname to a restricted directory ('path traversal') (CVE-ID: CVE-2026-64790)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to incorrect handling of path names in CUPS. A local application can gain elevated privileges.


56) Improper input validation (CVE-ID: CVE-2026-43692)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an unspecified flaw in CUPS when interacting with CUPS from a local application. A local user can execute a local application to cause a denial of service.


57) Improper input validation (CVE-ID: CVE-2026-84554)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 5.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in CUPS when processing input. A remote attacker can provide crafted input to cause a denial of service.


58) Improper limitation of a pathname to a restricted directory ('path traversal') (CVE-ID: CVE-2026-43691)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to incorrect handling of path names in CUPS. A local application can gain root privileges.


59) Improper input validation (CVE-ID: CVE-2026-84541)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to insufficient input validation in CUPS. A local application can trick the victim into opening a specially crafted file and access restricted files.


60) State issues (CVE-ID: CVE-2026-84540)

CWE-ID: CWE-371 - State Issues

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a state management issue in CUPS. A local application can access sensitive user data.


61) Memory corruption (CVE-ID: CVE-2026-84516)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in CUPS. A local application can trick the victim into opening a specially crafted file and perform a denial of service (DoS) attack.


62) Information disclosure (CVE-ID: CVE-2026-84612)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to an unspecified flaw in DeviceCheck when used by a local application. A local user can use a local application to gain access to sensitive information.


63) Out-of-bounds write (CVE-ID: CVE-2026-84505)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to an out-of-bounds write in Directory Utility. A local application can gain root privileges.


64) Memory corruption (CVE-ID: CVE-2026-84565)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in Disk Images. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.


65) Memory corruption (CVE-ID: CVE-2026-84552)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in Disk Images. A local application can cause unexpected system termination.


66) Improper input validation (CVE-ID: CVE-2026-84550)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service (DoS).

The vulnerability exists due to an unspecified flaw in Disk Images when a local application interacts with Disk Images. A local user can use a local application to cause a denial of service (DoS).


67) Improper access control (CVE-ID: CVE-2026-65362)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to improper access restrictions in Disk Images. A local application can gain root privileges.


68) Memory corruption (CVE-ID: CVE-2026-84512)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper restriction of operations within the bounds of a memory buffer in Disk Images when processing disk images. A local user can cause the vulnerable component to process a disk image to escalate privileges on the system.


69) Memory corruption (CVE-ID: CVE-2026-84510)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 2.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper restriction of operations within the bounds of a memory buffer in exFAT when processing exFAT file systems. A remote attacker can trigger the vulnerability to cause a denial of service.


70) Out-of-bounds write (CVE-ID: CVE-2026-86901)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds write in exFAT when processing an exFAT file system. A local user can provide a malformed exFAT file system to cause a denial of service.


71) Improper input validation (CVE-ID: CVE-2026-86900)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper input validation in exFAT when processing exFAT file systems. A local user can trigger the vulnerability to cause a denial of service.


72) Permissions, privileges, and access controls (CVE-ID: CVE-2026-43785)

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to improperly imposed security restrictions in File Bookmark. A local application can trick the victim into opening a specially crafted file and modify a file it only had permission to read.


73) Improper limitation of a pathname to a restricted directory ('path traversal') (CVE-ID: CVE-2026-84534)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to incorrect handling of path names in file_cmds. A remote attacker can trick the victim into opening a specially crafted file and escalate privileges on the system.


74) Improper input validation (CVE-ID: CVE-2026-43688)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation in Filters. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.


75) Memory corruption (CVE-ID: CVE-2026-84524)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in FontParser. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.


76) Improper input validation (CVE-ID: CVE-2026-84597)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to insufficient input validation in FontParser. A remote attacker can trick the victim into opening a specially crafted file and gain access to sensitive information.


77) Improper access control (CVE-ID: CVE-2026-84569)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper access restrictions in Foundation. A local application can access sensitive user data.


78) Memory corruption (CVE-ID: CVE-2026-65409)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in Foundation. A local application can cause a denial of service.


79) Protection mechanism failure (CVE-ID: CVE-2026-86911)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to bypass implemented security restrictions.

The vulnerability exists due to insufficient implementation of security measures in Foundation. A local application can bypass clickjacking protections for secure prompts.


80) Improper input validation (CVE-ID: CVE-2026-84618)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to insufficient input validation in Game Center. A local application can access sensitive user data.


81) State issues (CVE-ID: CVE-2026-84492)

CWE-ID: CWE-371 - State Issues

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a state management issue in Graphics. A local application can cause unexpected system termination.


82) Improper input validation (CVE-ID: CVE-2026-84533)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to an unspecified flaw in Heimdal when using the component. A local user can exploit the vulnerability to escalate privileges on the system.


83) Heap-based buffer overflow (CVE-ID: CVE-2022-3437)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. A remote user can send specially crafted data to the application, trigger a heap-based buffer overflow and perform a denial of service (DoS) attack.



84) Memory corruption (CVE-ID: CVE-2026-84581)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper restriction of operations within the bounds of a memory buffer in HFS when interacting with the HFS component. A local user can exploit the flaw to escalate privileges on the system.


85) Memory corruption (CVE-ID: CVE-2026-28934)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper restriction of operations within the bounds of a memory buffer in HFS when handling HFS filesystem operations. A local user can trigger the flaw through HFS filesystem operations to cause a denial of service.


86) Information disclosure (CVE-ID: CVE-2026-84606)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to track users.

The vulnerability exists due to excessive data output in iCloud. A local application can identify a user across reinstalls.


87) Improper limitation of a pathname to a restricted directory ('path traversal') (CVE-ID: CVE-2026-64756)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to incorrect handling of path names in Image Capture. A local application can access user-sensitive data.


88) Memory corruption (CVE-ID: CVE-2026-64714)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in ImageIO. A remote attacker can trick the victim into opening a specially crafted file and perform a denial-of-service.


89) Improper input validation (CVE-ID: CVE-2026-84564)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access sensitive information.

The vulnerability exists due to an unspecified flaw in ImageIO when processing input. A remote attacker can cause ImageIO to process input to access sensitive information.


90) Out-of-bounds write (CVE-ID: CVE-2026-86869)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds write in ImageIO. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.


91) Out-of-bounds write (CVE-ID: CVE-2026-65395)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to write data outside of intended memory bounds.

The vulnerability exists due to an out-of-bounds write in ImageIO when processing input. A remote attacker can send specially crafted input to the affected component to write data outside of intended memory bounds.


92) Use after free (CVE-ID: CVE-2026-28969)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a use-after-free error in IOKit. A local application can cause unexpected system termination.


93) Memory corruption (CVE-ID: CVE-2026-65398)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a boundary error in IOMobileFrameBuffer. A local application can cause unexpected system termination or corrupt kernel memory.


94) Information disclosure (CVE-ID: CVE-2026-64760)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to potentially sensitive information.

The vulnerability exists due to an error in IOSurfaceAccelerator. A local application can read sensitive kernel state.


95) Permissions, privileges, and access controls (CVE-ID: CVE-2026-65354)

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to improperly imposed security restrictions in iWork. A local application can break out of its sandbox.


96) Improper input validation (CVE-ID: CVE-2026-84588)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper input validation in the kernel when handling input. A local user can provide crafted input to escalate privileges on the system.


97) Out-of-bounds write (CVE-ID: CVE-2026-28968)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to an out-of-bounds write in Kernel. A local application can cause unexpected system termination or corrupt kernel memory.


98) Memory corruption (CVE-ID: CVE-2026-84566)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper restriction of operations within the bounds of a memory buffer in the kernel when vulnerable kernel code is executed. A local user can trigger the flaw to escalate privileges on the system.


99) Resource exhaustion (CVE-ID: CVE-2026-65415)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an unspecified flaw in the kernel when processing local user actions. A local user can interact with the kernel to cause a denial of service.


100) Improper input validation (CVE-ID: CVE-2026-84561)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to an unspecified flaw in the kernel when executing a local application. A local user can execute a local application to escalate privileges on the system.


101) State issues (CVE-ID: CVE-2026-84630)

CWE-ID: CWE-371 - State Issues

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a state management issue in Kernel. A local application can cause unexpected system termination.


102) State issues (CVE-ID: CVE-2026-65401)

CWE-ID: CWE-371 - State Issues

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a state management issue in Kernel. A local application can cause unexpected system termination.


103) State issues (CVE-ID: CVE-2026-65360)

CWE-ID: CWE-371 - State Issues

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a state management issue in Kernel. A local application can cause unexpected system termination.


104) State issues (CVE-ID: CVE-2026-65358)

CWE-ID: CWE-371 - State Issues

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a state management issue in Kernel. A local application can cause unexpected system termination.


105) Improper input validation (CVE-ID: CVE-2026-84558)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an unspecified flaw in the kernel when a local application interacts with the kernel. A local user can use a local application to cause a denial of service.


106) Memory corruption (CVE-ID: CVE-2026-65377)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in Kernel. A local application can cause unexpected system termination.


107) Memory corruption (CVE-ID: CVE-2026-84622)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a boundary error in Kernel. A local application can read uninitialized kernel memory.


108) Memory corruption (CVE-ID: CVE-2026-84549)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper restriction of operations within bounds of a memory buffer in the kernel when performing affected kernel operations. A local user can trigger the vulnerability to escalate privileges on the system.


109) Permissions, privileges, and access controls (CVE-ID: CVE-2026-43689)

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to improperly imposed security restrictions in Kernel. A local application can gain root privileges.


110) Out-of-bounds write (CVE-ID: CVE-2026-84619)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to an out-of-bounds write in Kernel. A local application can cause unexpected system termination or write kernel memory.


111) State issues (CVE-ID: CVE-2026-65369)

CWE-ID: CWE-371 - State Issues

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a state management issue in Kernel. A local application can gain access to sensitive information.


112) Permissions, privileges, and access controls (CVE-ID: CVE-2026-86917)

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to improperly imposed security restrictions in Kernel. A local application can gain root privileges.


113) Improper input validation (CVE-ID: CVE-2026-84544)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper input validation in the kernel when handling input. A local user can provide crafted input to escalate privileges on the system.


114) Memory corruption (CVE-ID: CVE-2026-43790)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to a boundary error in Kernel. A remote attacker can trick the victim into opening a specially crafted file and cause unexpected system termination or corrupt kernel memory.


115) Memory corruption (CVE-ID: CVE-2026-43687)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper restriction of operations within the bounds of a memory buffer in the kernel when processing input. A local user can interact with the kernel to disclose sensitive information.


116) Use-after-free (CVE-ID: CVE-2026-43686)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error in OS kernel when handling responses from an NFS server. A remote attacker can trick the victim into connecting to a malicious NFS server, trigger a use-after-free error and execute arbitrary code on the system.



117) Improper input validation (CVE-ID: CVE-2026-84538)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation in Kernel. A remote attacker can trick the victim into opening a specially crafted file and cause a denial-of-service.


118) Use-after-free (CVE-ID: CVE-2026-43684)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service attack.

The vulnerability exists due to a use-after-free error within the OS kernel. A local application can trigger memory corruption and crash the OS kernel. 


119) Improper initialization (CVE-ID: CVE-2026-65405)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper initialization within the OS kernel. A local local application can determine kernel memory layout.


120) Memory corruption (CVE-ID: CVE-2026-65364)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in Kernel. A remote attacker can trick the victim into opening a specially crafted file and cause unexpected system termination.


121) Improper input validation (CVE-ID: CVE-2026-84530)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to an unspecified flaw in the kernel when a local application interacts with it. A local user can use a local application to gain access to sensitive information.


122) Use after free (CVE-ID: CVE-2026-84521)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a use-after-free error in Kernel. A local application can cause unexpected system termination.


123) Use after free (CVE-ID: CVE-2026-65402)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a use-after-free error in Kernel. A local application can cause unexpected system termination.


124) Memory corruption (CVE-ID: CVE-2026-65359)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in Kernel. A local user can cause unexpected system termination or read kernel memory.


125) Improper input validation (CVE-ID: CVE-2026-84517)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation in Kernel. A local application can cause unexpected system termination.


126) State issues (CVE-ID: CVE-2026-84507)

CWE-ID: CWE-371 - State Issues

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a state management issue in Kernel. A local application can cause unexpected system termination or corrupt kernel memory.


127) Improper input validation (CVE-ID: CVE-2026-86903)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to insufficient input validation in Kernel. A local application can disclose kernel memory.


128) Improper access control (CVE-ID: CVE-2026-84602)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to improper access restrictions in Kernel. A local application can cause unexpected system termination.


129) Improper access control (CVE-ID: CVE-2026-84514)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to improper access restrictions in Kext Management. A local application can modify protected parts of the file system.


130) Improper input validation (CVE-ID: CVE-2026-84556)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to an unspecified flaw in Keychain Access when a local application interacts with it. A local user can use a local application to interact with Keychain Access to gain access to sensitive information.


131) Improper limitation of a pathname to a restricted directory ('path traversal') (CVE-ID: CVE-2026-65382)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to incorrect handling of path names in LaunchServices. A local application can trick the victim into opening a specially crafted file and access sensitive user data.


132) Memory corruption (CVE-ID: CVE-2026-86870)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in libarchive. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.


133) Improper access control (CVE-ID: CVE-2026-86894)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to improper access restrictions in libxpc. A local application can break out of its sandbox.


134) Improper access control (CVE-ID: CVE-2026-84577)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to bypass implemneted security restrictions.

The vulnerability exists due to improper access restrictions in libxpc. A local application can bypass sandbox restrictions.


135) Improper access control (CVE-ID: CVE-2026-84573)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper access restrictions in Mail. A local application can access sensitive user data.


136) Information disclosure (CVE-ID: CVE-2026-43787)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 4.8 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a logic issue in Mail. A remote attacker with access to the local network can send a specially crafted email to the victim and obtain sensitive user information. 


137) State issues (CVE-ID: CVE-2026-84628)

CWE-ID: CWE-371 - State Issues

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a state management issue in MediaRemote. A local application can access the System Keychain.


138) State issues (CVE-ID: CVE-2026-43741)

CWE-ID: CWE-371 - State Issues

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a state management issue in Messages. A local application can access protected user data.


139) Improper input validation (CVE-ID: CVE-2026-86924)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper input validation in MobileAccessoryUpdater when processing input. A local user can provide crafted input to cause a denial of service.


140) Improper input validation (CVE-ID: CVE-2026-84497)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an unspecified flaw in Model I/O when handling remote input. A remote attacker can interact with the vulnerable component remotely to cause a denial of service.


141) State issues (CVE-ID: CVE-2026-84585)

CWE-ID: CWE-371 - State Issues

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a state management issue in NetworkExtension. A local application can access local network devices without user consent.


142) State issues (CVE-ID: CVE-2026-43695)

CWE-ID: CWE-371 - State Issues

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a state management issue in NetworkExtension. A local application can access sensitive user data.


143) Information disclosure (CVE-ID: CVE-2026-84626)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in NetworkExtension. A local application can identify, which other applications were installed by the user. 


144) Improper limitation of a pathname to a restricted directory ('path traversal') (CVE-ID: CVE-2026-86902)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to incorrect handling of path names in NSDocument. A local application can trick the victim into opening a specially crafted file and access sensitive user data.


145) Improper access control (CVE-ID: CVE-2026-64712)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to improper access restrictions in odproxyd. A local application can gain root privileges.


146) Permissions, privileges, and access controls (CVE-ID: CVE-2026-84491)

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improperly imposed security restrictions in Photos Storage. A local application can access sensitive user data.


147) Improper access control (CVE-ID: CVE-2026-84580)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to improper access restrictions in quarantine. A local application can break out of its sandbox.


148) Improper access control (CVE-ID: CVE-2026-84578)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to improper access restrictions in quarantine. A local application can break out of its sandbox.


149) Improper access control (CVE-ID: CVE-2026-84576)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper access restrictions in QuartzCore. A local application can access sensitive user data.


150) Improper input validation (CVE-ID: CVE-2026-84548)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to insufficient input validation in Quick Look. A remote attacker can trick the victim into opening a specially crafted file and perform an out-of-bounds read.


151) Out-of-bounds write (CVE-ID: CVE-2026-28966)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds write in RealityKit. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.


152) Improper input validation (CVE-ID: CVE-2026-84532)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation in RealityKit. A remote attacker can trick the victim into opening a specially crafted file and perform a denial of service (DoS) attack.


153) Improper access control (CVE-ID: CVE-2026-65403)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper access restrictions in Reminders. A local application can access sensitive user data.


154) Information disclosure (CVE-ID: CVE-2026-84518)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in Safari. A remote attacker can determine, which applications are installed by the user.


155) Improper access control (CVE-ID: CVE-2026-86897)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper access restrictions in Safe Browsing. A local application can access sensitive user data.


156) Improper input validation (CVE-ID: CVE-2026-65380)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to access sensitive information.

The vulnerability exists due to an unspecified flaw in the Sandbox when a local application interacts with the sandbox. A local user can use a local application to access sensitive information.


157) Improper authorization (CVE-ID: CVE-2026-84555)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to bypass implemented security restrictions.

The vulnerability exists due to an error in Sandbox. A local application can gain access to sensitive user data.


158) Improper input validation (CVE-ID: CVE-2026-84551)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to bypass implemneted security restrictions.

The vulnerability exists due to insufficient input validation in Sandbox. A local application can bypass network restrictions.


159) Improper access control (CVE-ID: CVE-2026-84625)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to bypass sandbox restrictions.

The vulnerability exists due to improper access control in Sandbox Profiles when executing a local application. A local user can execute a local application to bypass sandbox restrictions.


160) Memory corruption (CVE-ID: CVE-2026-43697)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to a boundary error in SceneKit. A remote attacker can trick the victim into opening a specially crafted file and perform an out-of-bounds read.


161) Improper input validation (CVE-ID: CVE-2026-84487)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to insufficient input validation in SceneKit. A remote attacker can trick the victim into opening a specially crafted file and gain access to sensitive information.


162) Improper input validation (CVE-ID: CVE-2026-65413)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation in SceneKit. A local application can cause a denial of service.


163) Buffer overflow (CVE-ID: CVE-2026-84632)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in SceneKit when processing 3D models. A remote attacker can trick the victim into opening a specially crafted file, trigger memory corruption and execute arbitrary code on the target system.



164) Integer overflow (CVE-ID: CVE-2026-84620)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in SceneKit when processing 3D models. A remote attacker can trick the victim into opening a specially crafted file, trigger an integer overflow and execute arbitrary code on the target system.



165) Out-of-bounds write (CVE-ID: CVE-2026-84546)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause memory corruption.

The vulnerability exists due to an out-of-bounds write in SceneKit when processing remote input. A remote attacker can provide crafted input to cause memory corruption.


166) Out-of-bounds write (CVE-ID: CVE-2026-84611)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause an out-of-bounds write.

The vulnerability exists due to an out-of-bounds write in SceneKit when processing remote input. A remote attacker can provide input to the affected component to cause an out-of-bounds write.


167) Out-of-bounds write (CVE-ID: CVE-2026-84526)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds write in SceneKit. A remote attacker can trick the victim into opening a specially crafted file and perform unexpected process termination.


168) Improper authentication (CVE-ID: CVE-2026-65400) Exploited

CWE-ID: CWE-287 - Improper Authentication

CVSSv4: 8.6 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authentication.

The vulnerability exists due to improper authentication in Screen Sharing when handling network authentication attempts. A remote attacker can send crafted authentication requests to bypass authentication.


169) Improper certificate validation (CVE-ID: CVE-2026-86889)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 8.6 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists due to improper certificate validation in Security component. A remote attacker on the local network can intercept network traffic.


170) Improper certificate validation (CVE-ID: CVE-2026-86881)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists due to improper certificate validation in Security component. A remote attacker with a compromised intermediate certificate authority can issue certificates with arbitrary extended key usages.


171) Out-of-bounds write (CVE-ID: CVE-2026-84531)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds write in Security. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.


172) Improper authorization (CVE-ID: CVE-2026-84600)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to bypass implemented security restrictions.

The vulnerability exists due to an authorization issue in Shortcuts. A malicious shortcut can send messages without user confirmation.


173) Permissions, privileges, and access controls (CVE-ID: CVE-2026-86884)

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improperly imposed security restrictions in Siri. A local application can access sensitive user data.


174) Improper input validation (CVE-ID: CVE-2026-43690)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an unspecified flaw in SMB when accessing the system locally. A local user can exploit the vulnerability to disclose sensitive information.


175) Use-after-free (CVE-ID: CVE-2026-43719)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to use-after-free in SMB when handling SMB requests. A remote attacker can send SMB requests to cause a denial of service.


176) Memory corruption (CVE-ID: CVE-2026-65376)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in SMB. A local application can cause unexpected system termination.


177) Memory corruption (CVE-ID: CVE-2026-84543)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper restriction of operations within the bounds of a memory buffer in SMB when handling SMB operations. A local user can exploit the flaw to escalate privileges on the system.


178) Memory corruption (CVE-ID: CVE-2026-84537)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a boundary error in SMB. A local application can cause unexpected system termination or corrupt kernel memory.


179) Improper input validation (CVE-ID: CVE-2026-84536)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in SMB when handling SMB requests. A remote attacker can send a specially crafted SMB request to cause a denial of service.


180) Memory corruption (CVE-ID: CVE-2026-65365)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an unspecified flaw in SMB when handling SMB requests. A remote attacker can send an SMB request to disclose sensitive information.


181) Out-of-bounds write (CVE-ID: CVE-2026-84515)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted input in SMB server. A remote attacker can trick the victim into connecting to a malicious SBM server, trigger an out-of-bounds write and execute arbitrary code on the target system.


182) Memory corruption (CVE-ID: CVE-2026-84509)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper restriction of operations within the bounds of a memory buffer in SMB when handling SMB requests. A remote attacker can send a specially crafted SMB request to cause a denial of service.


183) Improper input validation (CVE-ID: CVE-2026-84553)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation in smbx. A remote attacker can trick the victim into opening a specially crafted file and cause a denial-of-service.


184) Improper input validation (CVE-ID: CVE-2026-84609)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to an unspecified flaw in Software Update when a local application interacts with it. A local user can exploit the flaw to escalate privileges on the system.


185) Improper access control (CVE-ID: CVE-2026-65361)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper access restrictions in SoftwareUpdate. A local application can access sensitive user data.


186) State issues (CVE-ID: CVE-2026-65378)

CWE-ID: CWE-371 - State Issues

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a state management issue in Spotlight. A local application can access sensitive user data.


187) Information disclosure (CVE-ID: CVE-2026-84621)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an unspecified flaw in Spotlight when used by a local application. A local user can exploit the flaw to disclose sensitive information.


188) Improper input validation (CVE-ID: CVE-2026-43788)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation in Spotlight. A remote attacker can trick the victim into opening a specially crafted file and perform a denial-of-service or potentially disclose memory contents.


189) Permissions, privileges, and access controls (CVE-ID: CVE-2026-65348)

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to improperly imposed security restrictions in Storage. A local application can modify protected parts of the file system.


190) Permissions, privileges, and access controls (CVE-ID: CVE-2026-65345)

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improperly imposed security restrictions in Storage. A local application can access user-sensitive data.


191) Information disclosure (CVE-ID: CVE-2026-43791)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to an unspecified flaw in StorageKit when used by a local application. A local user can use a local application to gain access to sensitive information.


192) Inclusion of Sensitive Information in Log Files (CVE-ID: CVE-2026-84513)

CWE-ID: CWE-532 - Information Exposure Through Log Files

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to insertion of sensitive information into log files in the Symptom Framework when used by a local application. A local user can use a local application to disclose sensitive information.


193) Improper access control (CVE-ID: CVE-2026-65383)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper access restrictions in System Settings. A local application can gain access to sensitive information.


194) State issues (CVE-ID: CVE-2026-86909)

CWE-ID: CWE-371 - State Issues

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a state management issue in System Settings. A local application can bypass Gatekeeper checks.


195) Information exposure through log files (CVE-ID: CVE-2026-84527)

CWE-ID: CWE-532 - Information Exposure Through Log Files

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to inclusion of sensitive information into a log file in TCC. A local application can access sensitive user data.


196) Permissions, privileges, and access controls (CVE-ID: CVE-2026-84589)

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to improperly imposed security restrictions in TCC. A local application can modify Privacy preferences.


197) State issues (CVE-ID: CVE-2026-28937)

CWE-ID: CWE-371 - State Issues

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a state management issue in Terminal. A local application can access sensitive user data.


198) Improper authorization (CVE-ID: CVE-2026-43696)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper authorization in Touch Bar. A local application can intercept Touch Bar content.


199) Memory corruption (CVE-ID: CVE-2026-84572)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in udf. A local application can cause unexpected system termination or read kernel memory.


200) Use after free (CVE-ID: CVE-2026-84506)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a use-after-free error in udf. A local application can execute arbitrary code with kernel privileges.


201) Improper access control (CVE-ID: CVE-2026-28899)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper access restrictions in CoreServices. A local application can gain access to sensitive information.


202) Buffer overflow (CVE-ID: CVE-2026-65374)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing WebDav responses. A remote attacker can trick the victim into connecting to a malicious WebDav server, trigger memory corruption and execute arbitrary code on the target system.


203) Improper authorization (CVE-ID: CVE-2026-65375)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service attack.

The vulnerability exists due to improper authorization checks in WebDAV. A local application can crash the system.


204) Out-of-bounds write (CVE-ID: CVE-2026-43677)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds write in WebDAV. A local application can perform unexpected app termination.


205) State issues (CVE-ID: CVE-2026-84635)

CWE-ID: CWE-371 - State Issues

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a state management issue in WebKit. A remote attacker can trick the victim into opening a specially crafted file and perform an unexpected process termination.


206) Improper input validation (CVE-ID: CVE-2026-64753)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to insufficient input validation in WebKit. A local user can trick the victim into opening a specially crafted file and gain access to sensitive information.


207) Universal cross-site scripting (CVE-ID: CVE-2026-86898)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can trick the victim to open a specially crafted web archive and execute arbitrary HTML and script code in user's browser in context of vulnerable website.


208) Use-after-free (CVE-ID: CVE-2026-64718)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to use-after-free in WebKit Canvas when processing maliciously crafted web content. A remote attacker can send maliciously crafted web content to cause a denial of service.

User interaction is required to process the crafted web content.


209) Improper input validation (CVE-ID: CVE-2026-65393)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to insufficient input validation in Xcode IDE. A local application can access user-sensitive data.


210) State issues (CVE-ID: CVE-2026-84617)

CWE-ID: CWE-371 - State Issues

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a state management issue in XPC. A local application can access sensitive user data.


Remediation

Install update from vendor's website.