Early access: this site has moved to bugrater.com.

Security releases

Apple

iOS 27 and iPadOS 27

149034 Sep 14, 2026 Source: Vendor

Imported by the Apple release catcher from https://support.apple.com/en-us/149034. 126 CVE entries, 67 additional recognitions. Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://support.apple.com/en-us/149034
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

378 lines
Showing 151–200 of 377 matching · page 4 of 8 · clear filters
CVE-2026-86883 BR2026-0000-012377 Managed Configuration unclaimed
An app may be able to access sensitive user data
Credited as Stuart Wallace
CVE-2026-86883 BR2026-0000-012378 Managed Configuration unclaimed
An app may be able to access sensitive user data
Credited as Tristan Brennan
CVE-2026-84628 BR2026-0000-012379 MediaRemote unclaimed
A sandboxed app may be able to access the System Keychain
Credited as Myeonghun Pak
CVE-2026-84628 BR2026-0000-012380 MediaRemote unclaimed
A sandboxed app may be able to access the System Keychain
Credited as Nathaniel Oh (@calysteon)
CVE-2026-84628 BR2026-0000-012381 MediaRemote unclaimed
A sandboxed app may be able to access the System Keychain
Credited as Alan Banderas (@creeper4004)
CVE-2026-86924 BR2026-0000-012382 MobileAccessoryUpdater unclaimed
Connecting a malicious accessory may cause unexpected system termination
Credited as Matthew Zamat
CVE-2026-65411 BR2026-0000-012383 MobileBackup unclaimed
An app may be able to modify protected parts of the file system
Credited as Rodolphe Brunetti (@eisw0lf) of Lupus Nova
CVE-2026-84598 BR2026-0000-012384 MobileBackup unclaimed
An attacker with physical access to a trust-paired device may be able to read and write arbitrary files
Credited as Drin Raci of sentry.security
CVE-2026-84497 BR2026-0000-012385 Model I/O unclaimed
Opening a maliciously crafted file may lead to unexpected process termination
Credited as Yiğit Can YILMAZ (@yilmazcanyigit)
CVE-2026-84615 BR2026-0000-012386 Music unclaimed
An app may be able to access sensitive user data
Credited as Stanislav Jelezoglo
CVE-2026-43695 BR2026-0000-012387 NetworkExtension unclaimed
An app may be able to access sensitive user data
Credited as Claudio Bozzato
CVE-2026-43695 BR2026-0000-012388 NetworkExtension unclaimed
An app may be able to access sensitive user data
Credited as Francesco Benvenuto of Cisco Talos
CVE-2026-84626 BR2026-0000-012389 NetworkExtension unclaimed
An app may be able to identify what other apps a user has installed
Credited as Sindre Sorhus
CVE-2026-84626 BR2026-0000-012390 NetworkExtension unclaimed
An app may be able to identify what other apps a user has installed
Credited as Hoffcona of IES Red Team
CVE-2026-84629 BR2026-0000-012391 Photos Storage unclaimed
An app may be able to fingerprint the user
Credited as Stanislav Jelezoglo
CVE-2026-84623 BR2026-0000-012392 Power Management unclaimed
An app may be able to fingerprint the device
Credited as Ilya Andr (andrd3v)
CVE-2026-28966 BR2026-0000-012393 RealityKit unclaimed
Processing a maliciously crafted file may lead to unexpected app termination
Credited as stratan (@5tratan)
CVE-2026-84532 BR2026-0000-012394 RealityKit unclaimed
Opening a maliciously crafted file may cause unexpected process termination or disclose process memory
Credited as Hongsik Kim (mnur)
CVE-2026-84532 BR2026-0000-012395 RealityKit unclaimed
Opening a maliciously crafted file may cause unexpected process termination or disclose process memory
Credited as stratan (@5tratan)
CVE-2026-65403 BR2026-0000-012396 Reminders unclaimed
An app may be able to access sensitive user data
Credited as Rahul Raj
CVE-2026-84518 BR2026-0000-012397 Safari unclaimed
A malicious website may be able to determine what apps a user has installed
Credited as Bálint Magyar (balintmagyar.com)
CVE-2026-86897 BR2026-0000-012398 Safe Browsing unclaimed
An app may be able to access sensitive user data
Credited as Stuart Wallace
CVE-2026-84551 BR2026-0000-012399 Sandbox unclaimed
An app may be able to bypass network restrictions
Credited as Issa Sancho
CVE-2026-84625 BR2026-0000-012400 Sandbox Profiles unclaimed
An app may be able to fingerprint the user
Credited as Ilya Andr (andrd3v) of Positive Technologies
CVE-2026-84625 BR2026-0000-012401 Sandbox Profiles unclaimed
An app may be able to fingerprint the user
Credited as CJ Vana
CVE-2026-84603 BR2026-0000-012402 Sandbox Profiles unclaimed
An app may be able to access sensitive user data
Credited as Gongyu Ma (@Mezone0)
CVE-2026-84603 BR2026-0000-012403 Sandbox Profiles unclaimed
An app may be able to access sensitive user data
Credited as CJ Vana
CVE-2026-84603 BR2026-0000-012404 Sandbox Profiles unclaimed
An app may be able to access sensitive user data
Credited as Stanislav Jelezoglo
CVE-2026-84487 BR2026-0000-012405 SceneKit unclaimed
Processing a maliciously crafted file may result in disclosure of process memory
Credited as stratan (@5tratan)
CVE-2026-84487 BR2026-0000-012406 SceneKit unclaimed
Processing a maliciously crafted file may result in disclosure of process memory
Credited as Dhiyanesh Selvaraj (@redroot97)
CVE-2026-84487 BR2026-0000-012407 SceneKit unclaimed
Processing a maliciously crafted file may result in disclosure of process memory
Credited as Peter Malone
CVE-2026-84632 BR2026-0000-012408 SceneKit unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as Peter Malone
CVE-2026-84620 BR2026-0000-012409 SceneKit unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as Peter Malone
CVE-2026-84546 BR2026-0000-012410 SceneKit unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as Narendra Singh (@_3P1C)
CVE-2026-84546 BR2026-0000-012411 SceneKit unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as stratan (@5tratan)
CVE-2026-84546 BR2026-0000-012412 SceneKit unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as Peter Malone
CVE-2026-84611 BR2026-0000-012413 SceneKit unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as Nathaniel Oh (@calysteon)
CVE-2026-84526 BR2026-0000-012414 SceneKit unclaimed
Processing a maliciously crafted 3D scene may lead to unexpected process termination
Credited as stratan (@5tratan)
CVE-2026-86881 BR2026-0000-012415 Security unclaimed
An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages
Credited as Surya Narayan Kushwaha
CVE-2026-86881 BR2026-0000-012416 Security unclaimed
An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages
Credited as Roman Zabicki
CVE-2026-86881 BR2026-0000-012417 Security unclaimed
An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages
Credited as John Lussier
CVE-2026-86881 BR2026-0000-012418 Security unclaimed
An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages
Credited as Filip Olszak
CVE-2026-84531 BR2026-0000-012419 Security unclaimed
Processing maliciously crafted NTLM input may lead to unexpected app termination
Credited as Meshaal (@unrealmesh)
CVE-2026-84600 BR2026-0000-012420 Shortcuts unclaimed
A malicious shortcut may be able to send messages without user confirmation
Credited as Owen Pawling (@owenpawling)
CVE-2026-86884 BR2026-0000-012421 Siri unclaimed
An app may be able to access sensitive user data
Credited as Stanislav Jelezoglo
CVE-2026-86884 BR2026-0000-012422 Siri unclaimed
An app may be able to access sensitive user data
Credited as Gongyu Ma (twitter @Mezone0)
CVE-2026-86890 BR2026-0000-012423 Siri Suggestions unclaimed
An attacker with physical access to a locked device may be able to view sensitive user information
Credited as Abhay Kailasia (@abhay_kailasia) from Safran Mumbai India
CVE-2026-84609 BR2026-0000-012424 Software Update unclaimed
An app may be able to modify protected system files
Credited as YingMuo (@YingMuo) of DEVCORE Research Team
CVE-2026-84621 BR2026-0000-012425 Spotlight unclaimed
An app may be able to access sensitive user data
Credited as Abodi Dawoud
CVE-2026-84621 BR2026-0000-012426 Spotlight unclaimed
An app may be able to access sensitive user data
Credited as Armend Gashi