Apple
iOS 27 and iPadOS 27
149034 Sep 14, 2026 Source: Vendor
Imported by the Apple release catcher from https://support.apple.com/en-us/149034. 126 CVE entries, 67 additional recognitions. Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://support.apple.com/en-us/149034
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
378 lines
Showing 201–250 of 377 matching · page 5 of 8 · clear filters
CVE-2026-84621
BR2026-0000-012427
Spotlight
unclaimed
An app may be able to access sensitive user data
Credited as Ujjwal Reddy Kalvolu Sreenivasa Reddy
CVE-2026-84621
BR2026-0000-012428
Spotlight
unclaimed
An app may be able to access sensitive user data
Credited as Johan Wahyudi
CVE-2026-86892
BR2026-0000-012429
SpringBoard
unclaimed
An app may be able to cause a denial-of-service
Credited as Lehan Dilusha Jayasingha
CVE-2026-65348
BR2026-0000-012430
Storage
unclaimed
An app may be able to modify protected parts of the file system
Credited as Jérôme Djouder
CVE-2026-65345
BR2026-0000-012431
Storage
unclaimed
An app may be able to access user-sensitive data
Credited as Seung Je Seong
CVE-2026-65345
BR2026-0000-012432
Storage
unclaimed
An app may be able to access user-sensitive data
Credited as Ilya Andr (andrd3v) of Positive Technologies
CVE-2026-65345
BR2026-0000-012433
Storage
unclaimed
An app may be able to access user-sensitive data
Credited as Jakob Pammer
CVE-2026-65345
BR2026-0000-012434
Storage
unclaimed
An app may be able to access user-sensitive data
Credited as 이재영
CVE-2026-84513
BR2026-0000-012435
Symptom Framework
unclaimed
A malicious application may be able to determine a user's current location
Credited as Sindre Sorhus
CVE-2026-86886
BR2026-0000-012436
TCC
unclaimed
An app may be able to modify protected system files
Credited as Constantin Clerc
CVE-2026-86886
BR2026-0000-012437
TCC
unclaimed
An app may be able to modify protected system files
Credited as Shad J
CVE-2026-86886
BR2026-0000-012438
TCC
unclaimed
An app may be able to modify protected system files
Credited as huami1314 (@huamidev)
CVE-2026-86886
BR2026-0000-012439
TCC
unclaimed
An app may be able to modify protected system files
Credited as Huy Nguyen (@34306) of Calif.io
CVE-2026-84527
BR2026-0000-012440
TCC
unclaimed
An app may be able to access sensitive user data
Credited as Zeyang Li&Yuxiang Wang of Chongqing Telecom
CVE-2026-65329
BR2026-0000-012441
Telephony
unclaimed
An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic
Credited as Bedran Karakoc
CVE-2026-65329
BR2026-0000-012442
Telephony
unclaimed
An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic
Credited as Tobias Funke
CVE-2026-65329
BR2026-0000-012443
Telephony
unclaimed
An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic
Credited as Jacopo Clark
CVE-2026-65329
BR2026-0000-012444
Telephony
unclaimed
An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic
Credited as Katharina Kohls of Ruhr University Bochum
CVE-2026-86904
BR2026-0000-012445
Watch App
unclaimed
An app may be able to track users across apps and websites without permission
Credited as Stanislav Jelezoglo
CVE-2026-84635
BR2026-0000-012446
WebKit
unclaimed
Processing maliciously crafted web content may lead to an unexpected process termination
Credited as Souta Sugiyama
CVE-2026-64753
BR2026-0000-012447
WebKit
unclaimed
Processing maliciously crafted web content may disclose sensitive user information
Credited as Viggo Lekdorf
CVE-2026-86898
BR2026-0000-012448
WebKit
unclaimed
Opening a maliciously crafted webarchive file may lead to universal cross-site scripting
Credited as Tomi Garcia (archyxsec)
CVE-2026-64718
BR2026-0000-012449
WebKit Canvas
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Niels Hofmans
CVE-2026-64718
BR2026-0000-012450
WebKit Canvas
unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as OGINOME Tomohito
CVE-2026-43674
BR2026-0000-012451
Wi-Fi3
unclaimed
An attacker with physical access to an unlocked device may be able to view Wi-Fi passwords without authentication
Credited as Yusuf Kelany
CVE-2026-84636
BR2026-0000-012452
Wi-Fi Connectivity
unclaimed
An app may be able to access sensitive user data
Credited as Jian Lee (@speedyfriend433)
CVE-2026-84617
BR2026-0000-012453
XPC
unclaimed
An app may be able to access sensitive user data
Credited as Stuart Wallace
Additional recognition
BR2026-0000-012454
Accessibility
unclaimed
Credited as Abhay Kailasia (@abhay_kailasia) from Safran Mumbai India
Additional recognition
BR2026-0000-012455
Accounts
unclaimed
Credited as Wojciech Regula of SecuRing (wojciechregula.blog)
Additional recognition
BR2026-0000-012456
AppleKeyStore
unclaimed
Credited as Abdurrahman Nafi
Additional recognition
BR2026-0000-012457
AppleKeyStore
unclaimed
Credited as Francisco Knabe
Additional recognition
BR2026-0000-012458
AppleKeyStore
unclaimed
Credited as Karol Mazurek (@Karmaz95) of AFINE
Additional recognition
BR2026-0000-012459
AppleKeyStore
unclaimed
Credited as Somair Ansar
Additional recognition
BR2026-0000-012460
AppleKeyStore
unclaimed
Credited as YOKI
Additional recognition
BR2026-0000-012461
AppleKeyStore
unclaimed
Credited as 晓娟 谢
Additional recognition
BR2026-0000-012462
Audio
unclaimed
Credited as Dhiyanesh Selvaraj (@redroot97)
Additional recognition
BR2026-0000-012463
AutoFill
unclaimed
Credited as Bistrit Dahal
Additional recognition
BR2026-0000-012464
AutoFill
unclaimed
Credited as Oussama Barbar
Additional recognition
BR2026-0000-012465
AutoFill
unclaimed
Credited as SalahAldeen Yousef
Additional recognition
BR2026-0000-012466
AVEVideoEncoder
unclaimed
Credited as tamdao
Additional recognition
BR2026-0000-012467
Baseband
unclaimed
Credited as Kai Tu
Additional recognition
BR2026-0000-012468
Baseband
unclaimed
Credited as Tianchang Yang
Additional recognition
BR2026-0000-012469
Baseband
unclaimed
Credited as Xiaotian Zhou
Additional recognition
BR2026-0000-012470
Baseband
unclaimed
Credited as Ali Ranjbar
Additional recognition
BR2026-0000-012471
Baseband
unclaimed
Credited as Abdullah Al Ishtiaq
Additional recognition
BR2026-0000-012472
Baseband
unclaimed
Credited as Tianwei Wu
Additional recognition
BR2026-0000-012473
Baseband
unclaimed
Credited as Yilu Dong
Additional recognition
BR2026-0000-012474
Baseband
unclaimed
Credited as Syed Rafiul Hussain — SyNSec Lab at Penn State
Additional recognition
BR2026-0000-012475
Bluetooth
unclaimed
Credited as David Maynor
Additional recognition
BR2026-0000-012476
Bluetooth
unclaimed
Credited as Jason Grove