SB2026091557 - Multiple vulnerabilities in Apple iOS 27 and iPadOS 27
Published: September 15, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 126 vulnerabilities.
1) Out-of-bounds write (CVE-ID: CVE-2026-86882)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds write in Accelerate Framework. A remote attacker can trick the victim into opening a specially crafted file and perform unexpected process termination.
2) Exposure of sensitive information to an unauthorized actor (CVE-ID: CVE-2026-43664)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to excessive data output in Accessibility. A local application can access sensitive user data.
3) Information disclosure (CVE-ID: CVE-2026-64761)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in Accessibility feature. A local application can identify other applications installed by the user.
4) Improper authorization (CVE-ID: CVE-2026-65404)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to bypass privacy preferences.
The vulnerability exists due to improper authorization checks in Accounts. A local application can bypass privacy preferences.
5) Out-of-bounds write (CVE-ID: CVE-2026-84523)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to an out-of-bounds write in APFS. A local application can cause unexpected system termination or write kernel memory.
6) Permissions, privileges, and access controls (CVE-ID: CVE-2026-86888)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improperly imposed security restrictions in App Store. A local application can read a persistent account identifier.
7) State issues (CVE-ID: CVE-2026-20683)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a state management issue in Apple Account. A local application can use the Sign In With Apple authentication flow to access the user\'s Apple Account.
8) Improper input validation (CVE-ID: CVE-2026-65408)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation in Apple Neural Engine. A local application can cause unexpected system termination.
9) Use after free (CVE-ID: CVE-2026-65407)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a use-after-free error in AppleAVD. A local application can cause unexpected system termination.
10) Out-of-bounds write (CVE-ID: CVE-2026-84519)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds write in AppleDouble. A remote attacker can trick the victim into opening a specially crafted file and perform unexpected system termination.
11) Use after free (CVE-ID: CVE-2026-84593)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a use-after-free error in AppleKeyStore. A local application can cause unexpected system termination.
12) Improper authorization (CVE-ID: CVE-2026-86905)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to delete credentials from Keychain.
The vulnerability exists due to missing authorization checks in Authentication Services. A local application can delete credentials stored in Keychain.
13) Permissions, privileges, and access controls (CVE-ID: CVE-2026-84583)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improperly imposed security restrictions in AuthKit. A local application can read a persistent account identifier.
14) Improper access control (CVE-ID: CVE-2026-65410)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to improper access restrictions in AVEVideoEncoder. A local application can cause unexpected system termination.
15) Memory corruption (CVE-ID: CVE-2026-84616)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in AVEVideoEncoder. A local application can cause unexpected system termination.
16) State issues (CVE-ID: CVE-2026-84607)
CWE-ID: CWE-371 - State Issues
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a state management issue in AVEVideoEncoder. A local application can execute arbitrary code with kernel privileges.
17) Improper input validation (CVE-ID: CVE-2026-65406)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to insufficient input validation in BackgroundAssets. A local application can access sensitive user data.
18) Improper input validation (CVE-ID: CVE-2026-86885)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the Baseband when processing input. A remote attacker can supply specially crafted input to cause a denial of service.
19) Improper input validation (CVE-ID: CVE-2026-86879)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation in Baseband. A remote attacker can trick the victim into opening a specially crafted file and cause a denial-of-service.
20) Out-of-bounds write (CVE-ID: CVE-2026-65414)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds write in Bluetooth. A remote attacker can trick the victim into opening a specially crafted file and cause unexpected app termination or arbitrary code execution.
21) State issues (CVE-ID: CVE-2026-84560)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a state management issue in Bluetooth. A local application can Bluetooth.
22) Permissions, privileges, and access controls (CVE-ID: CVE-2026-86878)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improperly imposed security restrictions in Camera. A local application can access sensitive user data.
23) State issues (CVE-ID: CVE-2026-86895)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a state management issue in CloudKit. A local application can read a persistent account identifier.
24) Permissions, privileges, and access controls (CVE-ID: CVE-2026-86893)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improperly imposed security restrictions in CloudKit. A local application can read device name.
25) Protection mechanism failure (CVE-ID: CVE-2026-65399)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to insufficient implementation of security measures in copyfile when copying data from an archive. A local user can bypass a file quarantine and bypass implemented security restrictions.
26) Improper input validation (CVE-ID: CVE-2026-64752)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to insufficient input validation in CoreMedia. A remote attacker can trick the victim into opening a specially crafted file and perform arbitrary code execution.
27) Out-of-bounds write (CVE-ID: CVE-2026-86876)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to an out-of-bounds write in CoreMedia when processing media content. A local user can trigger the out-of-bounds write to bypass implemented security restrictions.
28) Out-of-bounds write (CVE-ID: CVE-2026-65344)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds write in CoreMedia. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.
29) Improper input validation (CVE-ID: CVE-2026-84624)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an unspecified flaw in CoreML when a local application interacts with the component. A local user can use a local application to escalate privileges on the system.
30) Improper input validation (CVE-ID: CVE-2026-43737)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to insufficient input validation in CoreMotion. A local application can access motion data from headphones without user consent.
31) Improper input validation (CVE-ID: CVE-2026-65412)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation in CoreText. A remote attacker can trick the victim into opening a specially crafted file and perform a denial-of-service.
32) Memory corruption (CVE-ID: CVE-2026-84596)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to a boundary error in CoreText. A remote attacker can trick the victim into opening a specially crafted file and gain access to sensitive information.
33) Out-of-bounds write (CVE-ID: CVE-2026-84575)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds write in CoreUI. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.
34) Memory corruption (CVE-ID: CVE-2026-84489)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in CoreUI. A local application can cause a denial of service.
35) Memory corruption (CVE-ID: CVE-2026-84571)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in CoreUI. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.
36) Memory corruption (CVE-ID: CVE-2026-43738)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to a boundary error in CoreUI. A remote attacker can trick the victim into opening a specially crafted file and gain access to sensitive information.
37) Out-of-bounds write (CVE-ID: CVE-2026-84511)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds write in CoreUI. A remote attacker can trick the victim into opening a specially crafted file and perform unexpected process termination.
38) Information disclosure (CVE-ID: CVE-2026-84612)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to an unspecified flaw in DeviceCheck when used by a local application. A local user can use a local application to gain access to sensitive information.
39) Memory corruption (CVE-ID: CVE-2026-84552)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in Disk Images. A local application can cause unexpected system termination.
40) Memory corruption (CVE-ID: CVE-2026-84510)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 2.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper restriction of operations within the bounds of a memory buffer in exFAT when processing exFAT file systems. A remote attacker can trigger the vulnerability to cause a denial of service.
41) Permissions, privileges, and access controls (CVE-ID: CVE-2026-43785)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to improperly imposed security restrictions in File Bookmark. A local application can trick the victim into opening a specially crafted file and modify a file it only had permission to read.
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to incorrect handling of path names in file_cmds. A remote attacker can trick the victim into opening a specially crafted file and escalate privileges on the system.
43) Improper input validation (CVE-ID: CVE-2026-43688)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation in Filters. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.
44) Memory corruption (CVE-ID: CVE-2026-84524)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in FontParser. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.
45) Improper input validation (CVE-ID: CVE-2026-84597)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient input validation in FontParser. A remote attacker can trick the victim into opening a specially crafted file and gain access to sensitive information.
46) Memory corruption (CVE-ID: CVE-2026-65409)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in Foundation. A local application can cause a denial of service.
47) State issues (CVE-ID: CVE-2026-84492)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a state management issue in Graphics. A local application can cause unexpected system termination.
48) Improper input validation (CVE-ID: CVE-2026-84533)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an unspecified flaw in Heimdal when using the component. A local user can exploit the vulnerability to escalate privileges on the system.
49) Information disclosure (CVE-ID: CVE-2026-84606)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to track users.
The vulnerability exists due to excessive data output in iCloud. A local application can identify a user across reinstalls.
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to incorrect handling of path names in Image Capture. A local application can access user-sensitive data.
51) Improper input validation (CVE-ID: CVE-2026-84564)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access sensitive information.
The vulnerability exists due to an unspecified flaw in ImageIO when processing input. A remote attacker can cause ImageIO to process input to access sensitive information.
52) Out-of-bounds write (CVE-ID: CVE-2026-65395)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to write data outside of intended memory bounds.
The vulnerability exists due to an out-of-bounds write in ImageIO when processing input. A remote attacker can send specially crafted input to the affected component to write data outside of intended memory bounds.
53) Use after free (CVE-ID: CVE-2026-28969)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a use-after-free error in IOKit. A local application can cause unexpected system termination.
54) Memory corruption (CVE-ID: CVE-2026-65398)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a boundary error in IOMobileFrameBuffer. A local application can cause unexpected system termination or corrupt kernel memory.
55) Information disclosure (CVE-ID: CVE-2026-64760)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to potentially sensitive information.
The vulnerability exists due to an error in IOSurfaceAccelerator. A local application can read sensitive kernel state.
56) Permissions, privileges, and access controls (CVE-ID: CVE-2026-65354)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to improperly imposed security restrictions in iWork. A local application can break out of its sandbox.
57) Out-of-bounds write (CVE-ID: CVE-2026-28968)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to an out-of-bounds write in Kernel. A local application can cause unexpected system termination or corrupt kernel memory.
58) Memory corruption (CVE-ID: CVE-2026-84566)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper restriction of operations within the bounds of a memory buffer in the kernel when vulnerable kernel code is executed. A local user can trigger the flaw to escalate privileges on the system.
59) Resource exhaustion (CVE-ID: CVE-2026-65415)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an unspecified flaw in the kernel when processing local user actions. A local user can interact with the kernel to cause a denial of service.
60) Improper input validation (CVE-ID: CVE-2026-84561)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an unspecified flaw in the kernel when executing a local application. A local user can execute a local application to escalate privileges on the system.
61) State issues (CVE-ID: CVE-2026-84630)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a state management issue in Kernel. A local application can cause unexpected system termination.
62) State issues (CVE-ID: CVE-2026-65360)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a state management issue in Kernel. A local application can cause unexpected system termination.
63) State issues (CVE-ID: CVE-2026-65358)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a state management issue in Kernel. A local application can cause unexpected system termination.
64) Memory corruption (CVE-ID: CVE-2026-65377)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in Kernel. A local application can cause unexpected system termination.
65) Memory corruption (CVE-ID: CVE-2026-84622)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a boundary error in Kernel. A local application can read uninitialized kernel memory.
66) Permissions, privileges, and access controls (CVE-ID: CVE-2026-43689)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to improperly imposed security restrictions in Kernel. A local application can gain root privileges.
67) Memory corruption (CVE-ID: CVE-2026-43687)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper restriction of operations within the bounds of a memory buffer in the kernel when processing input. A local user can interact with the kernel to disclose sensitive information.
68) Use-after-free (CVE-ID: CVE-2026-43686)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error in OS kernel when handling responses from an NFS server. A remote attacker can trick the victim into connecting to a malicious NFS server, trigger a use-after-free error and execute arbitrary code on the system.
69) Improper initialization (CVE-ID: CVE-2026-65405)
CWE-ID: CWE-665 - Improper Initialization
CVSSv4: 6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improper initialization within the OS kernel. A local local application can determine kernel memory layout.
70) Improper input validation (CVE-ID: CVE-2026-84530)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to an unspecified flaw in the kernel when a local application interacts with it. A local user can use a local application to gain access to sensitive information.
71) Use after free (CVE-ID: CVE-2026-84521)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a use-after-free error in Kernel. A local application can cause unexpected system termination.
72) Use after free (CVE-ID: CVE-2026-65402)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a use-after-free error in Kernel. A local application can cause unexpected system termination.
73) Memory corruption (CVE-ID: CVE-2026-65359)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in Kernel. A local user can cause unexpected system termination or read kernel memory.
74) State issues (CVE-ID: CVE-2026-84507)
CWE-ID: CWE-371 - State Issues
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a state management issue in Kernel. A local application can cause unexpected system termination or corrupt kernel memory.
75) Improper input validation (CVE-ID: CVE-2026-86903)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to insufficient input validation in Kernel. A local application can disclose kernel memory.
76) Improper access control (CVE-ID: CVE-2026-84602)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to improper access restrictions in Kernel. A local application can cause unexpected system termination.
77) Memory corruption (CVE-ID: CVE-2026-86870)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in libarchive. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.
78) Improper input validation (CVE-ID: CVE-2026-86883)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to insufficient input validation in Managed Configuration. A local application can trick the victim into opening a specially crafted file and access sensitive user data.
79) State issues (CVE-ID: CVE-2026-84628)
CWE-ID: CWE-371 - State Issues
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a state management issue in MediaRemote. A local application can access the System Keychain.
80) Improper input validation (CVE-ID: CVE-2026-86924)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in MobileAccessoryUpdater when processing input. A local user can provide crafted input to cause a denial of service.
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to incorrect handling of path names in MobileBackup. A local application can modify protected parts of the file system.
82) Improper input validation (CVE-ID: CVE-2026-84598)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to escalate privileges on the system.
The vulnerability exists due to an unspecified flaw in MobileBackup when using the component with physical access to the system. An attacker with physical access can exploit the vulnerability to escalate privileges on the system.
83) Improper input validation (CVE-ID: CVE-2026-84497)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an unspecified flaw in Model I/O when handling remote input. A remote attacker can interact with the vulnerable component remotely to cause a denial of service.
84) State issues (CVE-ID: CVE-2026-84615)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a state management issue in Music. A local application can access sensitive user data.
85) State issues (CVE-ID: CVE-2026-43695)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a state management issue in NetworkExtension. A local application can access sensitive user data.
86) Information disclosure (CVE-ID: CVE-2026-84626)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in NetworkExtension. A local application can identify, which other applications were installed by the user.
87) Permissions, privileges, and access controls (CVE-ID: CVE-2026-84491)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improperly imposed security restrictions in Photos Storage. A local application can access sensitive user data.
88) Information disclosure (CVE-ID: CVE-2026-84629)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to excessive data output in Photos Storage. A local application can fingerprint the user.
89) Improper authorization (CVE-ID: CVE-2026-84623)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improper authorization checks in Power Management. A local application can fingerprint the device.
90) Out-of-bounds write (CVE-ID: CVE-2026-28966)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds write in RealityKit. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.
91) Improper input validation (CVE-ID: CVE-2026-84532)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation in RealityKit. A remote attacker can trick the victim into opening a specially crafted file and perform a denial of service (DoS) attack.
92) Improper access control (CVE-ID: CVE-2026-65403)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improper access restrictions in Reminders. A local application can access sensitive user data.
93) Information disclosure (CVE-ID: CVE-2026-84518)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in Safari. A remote attacker can determine, which applications are installed by the user.
94) Improper access control (CVE-ID: CVE-2026-86897)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improper access restrictions in Safe Browsing. A local application can access sensitive user data.
95) Improper input validation (CVE-ID: CVE-2026-84551)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to bypass implemneted security restrictions.
The vulnerability exists due to insufficient input validation in Sandbox. A local application can bypass network restrictions.
96) Improper access control (CVE-ID: CVE-2026-84625)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass sandbox restrictions.
The vulnerability exists due to improper access control in Sandbox Profiles when executing a local application. A local user can execute a local application to bypass sandbox restrictions.
97) Permissions, privileges, and access controls (CVE-ID: CVE-2026-84603)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improperly imposed security restrictions in Sandbox Profiles. A local application can access sensitive user data.
98) Improper input validation (CVE-ID: CVE-2026-84487)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient input validation in SceneKit. A remote attacker can trick the victim into opening a specially crafted file and gain access to sensitive information.
99) Buffer overflow (CVE-ID: CVE-2026-84632)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in SceneKit when processing 3D models. A remote attacker can trick the victim into opening a specially crafted file, trigger memory corruption and execute arbitrary code on the target system.
100) Integer overflow (CVE-ID: CVE-2026-84620)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in SceneKit when processing 3D models. A remote attacker can trick the victim into opening a specially crafted file, trigger an integer overflow and execute arbitrary code on the target system.
101) Out-of-bounds write (CVE-ID: CVE-2026-84546)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in SceneKit when processing remote input. A remote attacker can provide crafted input to cause memory corruption.
102) Out-of-bounds write (CVE-ID: CVE-2026-84611)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause an out-of-bounds write.
The vulnerability exists due to an out-of-bounds write in SceneKit when processing remote input. A remote attacker can provide input to the affected component to cause an out-of-bounds write.
103) Out-of-bounds write (CVE-ID: CVE-2026-84526)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds write in SceneKit. A remote attacker can trick the victim into opening a specially crafted file and perform unexpected process termination.
104) Improper certificate validation (CVE-ID: CVE-2026-86881)
CWE-ID: CWE-295 - Improper Certificate Validation
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to improper certificate validation in Security component. A remote attacker with a compromised intermediate certificate authority can issue certificates with arbitrary extended key usages.
105) Out-of-bounds write (CVE-ID: CVE-2026-84531)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds write in Security. A local application can trick the victim into opening a specially crafted file and perform unexpected app termination.
106) Improper authorization (CVE-ID: CVE-2026-84600)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to an authorization issue in Shortcuts. A malicious shortcut can send messages without user confirmation.
107) Permissions, privileges, and access controls (CVE-ID: CVE-2026-86884)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improperly imposed security restrictions in Siri. A local application can access sensitive user data.
108) Improper access control (CVE-ID: CVE-2026-86890)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to the system to gain access to sensitive information.
The vulnerability exists due to improper access restrictions in Siri Suggestions. An attacker with physical access to the system can view sensitive user information.
109) Improper input validation (CVE-ID: CVE-2026-84609)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an unspecified flaw in Software Update when a local application interacts with it. A local user can exploit the flaw to escalate privileges on the system.
110) Information disclosure (CVE-ID: CVE-2026-84621)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an unspecified flaw in Spotlight when used by a local application. A local user can exploit the flaw to disclose sensitive information.
111) Improper access control (CVE-ID: CVE-2026-86892)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to perform a denial of service (DoS) attack.
The vulnerability exists due to improper access restrictions in SpringBoard. A local application can cause a denial-of-service.
112) Permissions, privileges, and access controls (CVE-ID: CVE-2026-65348)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to improperly imposed security restrictions in Storage. A local application can modify protected parts of the file system.
113) Permissions, privileges, and access controls (CVE-ID: CVE-2026-65345)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improperly imposed security restrictions in Storage. A local application can access user-sensitive data.
114) Inclusion of Sensitive Information in Log Files (CVE-ID: CVE-2026-84513)
CWE-ID: CWE-532 - Information Exposure Through Log Files
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to insertion of sensitive information into log files in the Symptom Framework when used by a local application. A local user can use a local application to disclose sensitive information.
115) Improper input validation (CVE-ID: CVE-2026-86886)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to insufficient input validation in TCC. A local application can trick the victim into opening a specially crafted file and modify protected system files.
116) Information exposure through log files (CVE-ID: CVE-2026-84527)
CWE-ID: CWE-532 - Information Exposure Through Log Files
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to inclusion of sensitive information into a log file in TCC. A local application can access sensitive user data.
117) Improper authentication (CVE-ID: CVE-2026-65329)
CWE-ID: CWE-287 - Improper Authentication
CVSSv4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to a state issue in the Telephony service. An remote attacker in the local network can bypass IPSec authentication and intercept network traffic.
118) Information disclosure (CVE-ID: CVE-2026-86887)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in Time Zone. A local application can bypass certain privacy preferences.
119) Information disclosure (CVE-ID: CVE-2026-86904)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to excessive data output in Watch App. A local application can track users across apps and websites without permission.
120) State issues (CVE-ID: CVE-2026-84635)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a state management issue in WebKit. A remote attacker can trick the victim into opening a specially crafted file and perform an unexpected process termination.
121) Improper input validation (CVE-ID: CVE-2026-64753)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to insufficient input validation in WebKit. A local user can trick the victim into opening a specially crafted file and gain access to sensitive information.
122) Universal cross-site scripting (CVE-ID: CVE-2026-86898)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can trick the victim to open a specially crafted web archive and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
123) Use-after-free (CVE-ID: CVE-2026-64718)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in WebKit Canvas when processing maliciously crafted web content. A remote attacker can send maliciously crafted web content to cause a denial of service.
User interaction is required to process the crafted web content.
124) State issues (CVE-ID: CVE-2026-43674)
CWE-ID: CWE-371 - State Issues
CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to the system to gain access to sensitive information.
The vulnerability exists due to a state management issue in Wi-Fi3. An attacker with physical access to the system can view Wi-Fi passwords without authentication.
125) State issues (CVE-ID: CVE-2026-84636)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a state management issue in Wi-Fi Connectivity. A local application can access sensitive user data.
126) State issues (CVE-ID: CVE-2026-84617)
CWE-ID: CWE-371 - State Issues
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a state management issue in XPC. A local application can access sensitive user data.
Remediation
Install update from vendor's website.
References
- https://support.apple.com/en-us/149042
- https://support.apple.com/en-us/149034
- https://support.apple.com/en-us/149035
- https://support.apple.com/en-us/128071
- https://support.apple.com/en-us/127115
- https://support.apple.com/en-us/148287
- https://support.apple.com/en-us/149041
- https://support.apple.com/en-us/149039
- https://support.apple.com/en-us/148282
- https://support.apple.com/en-us/128073
- https://bugs.webkit.org/show_bug.cgi?id=313935