Known vulnerabilities in visionOS 26.0 23M5328a - page 9

Vendor: Apple Inc.
Software: visionOS
Version: 26.0 23M5328a
Software CPE: cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
Total vulnerabilities: 299
Public exploits: 5
Known exploited (KEV): 5
Highest CVSSv4 Score: 8.8

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting visionOS version 26.0 23M5328a visionOS 26.0 23M5328a is affected by 299 vulnerabilities: 2 critical, 13 high, 64 medium, 220 low Critical High Medium Low

Vulnerabilities (299)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU124404 - Permissions, Privileges, and Access Controls
CVE-2026-28833
CWE-264 Low
No
No
26.4 25.03.2026 SB2026032504
SB2026032514
SB2026032541
#VU124403 - Permissions, Privileges, and Access Controls
CVE-2026-28880
CWE-264 Low
No
No
26.4 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 3 more
#VU124390 - Improper Access Control
CVE-2026-28867
CWE-284 Low
No
No
26.4 25.03.2026 SB2026032504
SB2026032506
SB2026032509
and 4 more
#VU124387 - Exposure of sensitive information to an unauthorized actor
CVE-2026-28870
CWE-200 Low
No
No
26.4 25.03.2026 SB2026032504
SB2026032514
SB2026032539
and 3 more
#VU124361 - Memory corruption
CVE-2026-20698
CWE-119 Low
No
No
26.4 25.03.2026 SB2026032504
SB2026032514
SB2026032539
and 2 more
#VU124360 - Information Exposure Through Log Files
CVE-2026-28868
CWE-532 Low
No
No
26.4 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 4 more
#VU124355 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-28876
CWE-22 Low
No
No
26.4 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 3 more
#VU124354 - Memory corruption
CVE-2026-28822
CWE-119 Low
No
No
26.4 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 4 more
#VU124352 - Improper input validation
CVE-2026-28886
CWE-20 Low
No
No
26.4 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 5 more
#VU124349 - Memory corruption
CVE-2026-20690
CWE-119 Low
No
No
26.4 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 5 more
#VU124346 - Use After Free
CVE-2026-28879
CWE-416 Medium
No
No
26.4 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 5 more
#VU124342 - Improper input validation
CVE-2026-28878
CWE-20 Low
No
No
26.4 25.03.2026 SB2026032504
SB2026032507
SB2026032509
and 5 more
#VU124336 - Improper Authorization
CVE-2026-28877
CWE-285 Low
No
No
26.4 25.03.2026 SB2026032504
SB2026032506
SB2026032514
and 3 more
#VU124335 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2026-28865
CWE-300 Medium
No
No
26.4 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 5 more
#VU122712 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-20677
CWE-362 Low
No
No
26.3 11.02.2026 SB2026021188
SB2026021190
SB2026021191
and 2 more
#VU122703 - Memory corruption
CVE-2026-20621
CWE-119 Low
No
No
26.3 11.02.2026 SB2026021188
SB2026021189
SB2026021190
and 3 more
#VU122671 - Memory corruption
CVE-2026-20636
CWE-119 Low
No
No
26.3 11.02.2026 SB2026021187
SB2026021188
SB2026021191
and 23 more
#VU122672 - Memory corruption
CVE-2026-20635
CWE-119 Low
No
No
26.3 11.02.2026 SB2026021187
SB2026021188
SB2026021191
and 26 more
#VU121026 - Insufficiently Protected Credentials
CVE-2025-14524
CWE-522 Low
No
No
26.4 07.01.2026 SB2026010741
SB2026010781
SB2026010782
and 23 more
#VU118780 - Out-of-bounds read
CVE-2025-64505
CWE-125 Medium
No
No
26.4 26.11.2025 SB2025112638
SB2025112639
SB2025112819
and 22 more


Showing elements 161 - 180 out of 299