SB2026091536 - Multiple vulnerabilities in Apple iOS 26 and iPadOS 26
Published: September 15, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 82 vulnerabilities.
1) Improper input validation (CVE-ID: CVE-2026-86924)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in MobileAccessoryUpdater when processing input. A local user can provide crafted input to cause a denial of service.
2) Improper access control (CVE-ID: CVE-2026-65403)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improper access restrictions in Reminders. A local application can access sensitive user data.
3) Out-of-bounds write (CVE-ID: CVE-2026-28966)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds write in RealityKit. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.
4) Improper input validation (CVE-ID: CVE-2026-84532)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation in RealityKit. A remote attacker can trick the victim into opening a specially crafted file and perform a denial of service (DoS) attack.
5) Improper authorization (CVE-ID: CVE-2026-84623)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improper authorization checks in Power Management. A local application can fingerprint the device.
6) Permissions, privileges, and access controls (CVE-ID: CVE-2026-84491)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improperly imposed security restrictions in Photos Storage. A local application can access sensitive user data.
7) Information disclosure (CVE-ID: CVE-2026-84626)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in NetworkExtension. A local application can identify, which other applications were installed by the user.
8) State issues (CVE-ID: CVE-2026-84615)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a state management issue in Music. A local application can access sensitive user data.
9) Improper input validation (CVE-ID: CVE-2026-84497)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an unspecified flaw in Model I/O when handling remote input. A remote attacker can interact with the vulnerable component remotely to cause a denial of service.
10) Improper input validation (CVE-ID: CVE-2026-84598)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to escalate privileges on the system.
The vulnerability exists due to an unspecified flaw in MobileBackup when using the component with physical access to the system. An attacker with physical access can exploit the vulnerability to escalate privileges on the system.
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to incorrect handling of path names in MobileBackup. A local application can modify protected parts of the file system.
12) Improper access control (CVE-ID: CVE-2026-86897)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improper access restrictions in Safe Browsing. A local application can access sensitive user data.
13) Memory corruption (CVE-ID: CVE-2026-86870)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in libarchive. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.
14) Memory corruption (CVE-ID: CVE-2026-65359)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in Kernel. A local user can cause unexpected system termination or read kernel memory.
15) Improper input validation (CVE-ID: CVE-2026-84561)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an unspecified flaw in the kernel when executing a local application. A local user can execute a local application to escalate privileges on the system.
16) State issues (CVE-ID: CVE-2026-84507)
CWE-ID: CWE-371 - State Issues
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a state management issue in Kernel. A local application can cause unexpected system termination or corrupt kernel memory.
17) Use after free (CVE-ID: CVE-2026-84521)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a use-after-free error in Kernel. A local application can cause unexpected system termination.
18) Use after free (CVE-ID: CVE-2026-65402)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a use-after-free error in Kernel. A local application can cause unexpected system termination.
19) Improper access control (CVE-ID: CVE-2026-84602)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to improper access restrictions in Kernel. A local application can cause unexpected system termination.
20) Memory corruption (CVE-ID: CVE-2026-84622)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a boundary error in Kernel. A local application can read uninitialized kernel memory.
21) Improper input validation (CVE-ID: CVE-2026-84530)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to an unspecified flaw in the kernel when a local application interacts with it. A local user can use a local application to gain access to sensitive information.
22) Improper access control (CVE-ID: CVE-2026-86892)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to improper access restrictions in SpringBoard. A local application can cause a denial-of-service.
23) State issues (CVE-ID: CVE-2026-84617)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a state management issue in XPC. A local application can access sensitive user data.
24) Use-after-free (CVE-ID: CVE-2026-64718)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in WebKit Canvas when processing maliciously crafted web content. A remote attacker can send maliciously crafted web content to cause a denial of service.
User interaction is required to process the crafted web content.
25) Use-after-free (CVE-ID: CVE-2026-43715)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in WebKit when rendering content. A remote attacker can craft malicious web content to execute arbitrary code.
26) Information disclosure (CVE-ID: CVE-2026-86904)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to excessive data output in Watch App. A local application can track users across apps and websites without permission.
27) Information disclosure (CVE-ID: CVE-2026-86887)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in Time Zone. A local application can bypass certain privacy preferences.
28) Improper input validation (CVE-ID: CVE-2026-86886)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to insufficient input validation in TCC. A local application can trick the victim into opening a specially crafted file and modify protected system files.
29) Inclusion of Sensitive Information in Log Files (CVE-ID: CVE-2026-84513)
CWE-ID: CWE-532 - Information Exposure Through Log Files
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to insertion of sensitive information into log files in the Symptom Framework when used by a local application. A local user can use a local application to disclose sensitive information.
30) Permissions, privileges, and access controls (CVE-ID: CVE-2026-65348)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to improperly imposed security restrictions in Storage. A local application can modify protected parts of the file system.
31) Permissions, privileges, and access controls (CVE-ID: CVE-2026-65345)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improperly imposed security restrictions in Storage. A local application can access user-sensitive data.
32) State issues (CVE-ID: CVE-2026-65360)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a state management issue in Kernel. A local application can cause unexpected system termination.
33) Information disclosure (CVE-ID: CVE-2026-84621)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an unspecified flaw in Spotlight when used by a local application. A local user can exploit the flaw to disclose sensitive information.
34) Improper access control (CVE-ID: CVE-2026-86890)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to the system to gain access to sensitive information.
The vulnerability exists due to improper access restrictions in Siri Suggestions. An attacker with physical access to the system can view sensitive user information.
35) Improper certificate validation (CVE-ID: CVE-2026-86881)
CWE-ID: CWE-295 - Improper Certificate Validation
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to improper certificate validation in Security component. A remote attacker with a compromised intermediate certificate authority can issue certificates with arbitrary extended key usages.
36) Out-of-bounds write (CVE-ID: CVE-2026-84526)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds write in SceneKit. A remote attacker can trick the victim into opening a specially crafted file and perform unexpected process termination.
37) Integer overflow (CVE-ID: CVE-2026-84620)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in SceneKit when processing 3D models. A remote attacker can trick the victim into opening a specially crafted file, trigger an integer overflow and execute arbitrary code on the target system.
38) Buffer overflow (CVE-ID: CVE-2026-84632)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in SceneKit when processing 3D models. A remote attacker can trick the victim into opening a specially crafted file, trigger memory corruption and execute arbitrary code on the target system.
39) Out-of-bounds write (CVE-ID: CVE-2026-84611)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause an out-of-bounds write.
The vulnerability exists due to an out-of-bounds write in SceneKit when processing remote input. A remote attacker can provide input to the affected component to cause an out-of-bounds write.
40) Out-of-bounds write (CVE-ID: CVE-2026-84546)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in SceneKit when processing remote input. A remote attacker can provide crafted input to cause memory corruption.
41) Improper input validation (CVE-ID: CVE-2026-84487)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient input validation in SceneKit. A remote attacker can trick the victim into opening a specially crafted file and gain access to sensitive information.
42) Improper input validation (CVE-ID: CVE-2026-65406)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to insufficient input validation in BackgroundAssets. A local application can access sensitive user data.
43) Memory corruption (CVE-ID: CVE-2026-84552)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in Disk Images. A local application can cause unexpected system termination.
44) Information disclosure (CVE-ID: CVE-2026-84612)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to an unspecified flaw in DeviceCheck when used by a local application. A local user can use a local application to gain access to sensitive information.
45) Improper input validation (CVE-ID: CVE-2026-65412)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation in CoreText. A remote attacker can trick the victim into opening a specially crafted file and perform a denial-of-service.
46) Improper input validation (CVE-ID: CVE-2026-43737)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to insufficient input validation in CoreMotion. A local application can access motion data from headphones without user consent.
47) Improper input validation (CVE-ID: CVE-2026-84624)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an unspecified flaw in CoreML when a local application interacts with the component. A local user can use a local application to escalate privileges on the system.
48) Memory corruption (CVE-ID: CVE-2026-43702)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a boundary error in CoreMedia Video Toolbox. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination or corrupt process memory.
49) Out-of-bounds write (CVE-ID: CVE-2026-86876)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to an out-of-bounds write in CoreMedia when processing media content. A local user can trigger the out-of-bounds write to bypass implemented security restrictions.
50) Out-of-bounds write (CVE-ID: CVE-2026-65344)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds write in CoreMedia. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.
51) Protection mechanism failure (CVE-ID: CVE-2026-65399)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to insufficient implementation of security measures in copyfile when copying data from an archive. A local user can bypass a file quarantine and bypass implemented security restrictions.
52) Out-of-bounds write (CVE-ID: CVE-2026-65414)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds write in Bluetooth. A remote attacker can trick the victim into opening a specially crafted file and cause unexpected app termination or arbitrary code execution.
53) Memory corruption (CVE-ID: CVE-2026-84510)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 2.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper restriction of operations within the bounds of a memory buffer in exFAT when processing exFAT file systems. A remote attacker can trigger the vulnerability to cause a denial of service.
54) State issues (CVE-ID: CVE-2026-84607)
CWE-ID: CWE-371 - State Issues
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a state management issue in AVEVideoEncoder. A local application can execute arbitrary code with kernel privileges.
55) Memory corruption (CVE-ID: CVE-2026-84616)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in AVEVideoEncoder. A local application can cause unexpected system termination.
56) Improper access control (CVE-ID: CVE-2026-65410)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to improper access restrictions in AVEVideoEncoder. A local application can cause unexpected system termination.
57) Permissions, privileges, and access controls (CVE-ID: CVE-2026-84583)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improperly imposed security restrictions in AuthKit. A local application can read a persistent account identifier.
58) Out-of-bounds write (CVE-ID: CVE-2026-84519)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds write in AppleDouble. A remote attacker can trick the victim into opening a specially crafted file and perform unexpected system termination.
59) Use after free (CVE-ID: CVE-2026-65407)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a use-after-free error in AppleAVD. A local application can cause unexpected system termination.
60) Improper input validation (CVE-ID: CVE-2026-65408)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation in Apple Neural Engine. A local application can cause unexpected system termination.
61) Out-of-bounds write (CVE-ID: CVE-2026-84523)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to an out-of-bounds write in APFS. A local application can cause unexpected system termination or write kernel memory.
62) Exposure of sensitive information to an unauthorized actor (CVE-ID: CVE-2026-43664)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to excessive data output in Accessibility. A local application can access sensitive user data.
63) State issues (CVE-ID: CVE-2026-43743)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a state management issue in IOGPUFamily. A local application can cause unexpected system termination.
64) State issues (CVE-ID: CVE-2026-84630)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a state management issue in Kernel. A local application can cause unexpected system termination.
65) Improper initialization (CVE-ID: CVE-2026-65405)
CWE-ID: CWE-665 - Improper Initialization
CVSSv4: 6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improper initialization within the OS kernel. A local local application can determine kernel memory layout.
66) Use-after-free (CVE-ID: CVE-2026-43686)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error in OS kernel when handling responses from an NFS server. A remote attacker can trick the victim into connecting to a malicious NFS server, trigger a use-after-free error and execute arbitrary code on the system.
67) Use-after-free (CVE-ID: CVE-2026-43684)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service attack.
The vulnerability exists due to a use-after-free error within the OS kernel. A local application can trigger memory corruption and crash the OS kernel.
68) Memory corruption (CVE-ID: CVE-2026-43687)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper restriction of operations within the bounds of a memory buffer in the kernel when processing input. A local user can interact with the kernel to disclose sensitive information.
69) Memory corruption (CVE-ID: CVE-2026-65377)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in Kernel. A local application can cause unexpected system termination.
70) Permissions, privileges, and access controls (CVE-ID: CVE-2026-43689)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to improperly imposed security restrictions in Kernel. A local application can gain root privileges.
71) Out-of-bounds write (CVE-ID: CVE-2026-28968)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to an out-of-bounds write in Kernel. A local application can cause unexpected system termination or corrupt kernel memory.
72) Memory corruption (CVE-ID: CVE-2026-84566)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper restriction of operations within the bounds of a memory buffer in the kernel when vulnerable kernel code is executed. A local user can trigger the flaw to escalate privileges on the system.
73) Out-of-bounds write (CVE-ID: CVE-2026-86882)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds write in Accelerate Framework. A remote attacker can trick the victim into opening a specially crafted file and perform unexpected process termination.
74) Out-of-bounds write (CVE-ID: CVE-2026-65395)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to write data outside of intended memory bounds.
The vulnerability exists due to an out-of-bounds write in ImageIO when processing input. A remote attacker can send specially crafted input to the affected component to write data outside of intended memory bounds.
75) Out-of-bounds write (CVE-ID: CVE-2026-86869)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds write in ImageIO. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.
76) Memory corruption (CVE-ID: CVE-2026-43661)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to a boundary error in ImageIO. A remote attacker can trick the victim into opening a specially crafted file and escalate privileges on the system.
77) Memory corruption (CVE-ID: CVE-2026-64758)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in ImageIO. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.
78) Improper input validation (CVE-ID: CVE-2026-84564)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access sensitive information.
The vulnerability exists due to an unspecified flaw in ImageIO when processing input. A remote attacker can cause ImageIO to process input to access sensitive information.
79) State issues (CVE-ID: CVE-2026-84492)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a state management issue in Graphics. A local application can cause unexpected system termination.
80) Memory corruption (CVE-ID: CVE-2026-65409)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in Foundation. A local application can cause a denial of service.
81) Memory corruption (CVE-ID: CVE-2026-84524)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in FontParser. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to incorrect handling of path names in file_cmds. A remote attacker can trick the victim into opening a specially crafted file and escalate privileges on the system.
Remediation
Install update from vendor's website.
References
- https://support.apple.com/en-us/149042
- https://support.apple.com/en-us/149041
- https://support.apple.com/en-us/149035
- https://support.apple.com/en-us/128073
- https://bugs.webkit.org/show_bug.cgi?id=313935
- https://support.apple.com/en-us/127595
- https://support.apple.com/en-us/149043
- https://support.apple.com/en-us/127115
- https://support.apple.com/en-us/128067