Early access: this site has moved to bugrater.com.

Security releases

Apple

iOS 27 and iPadOS 27

149034 Sep 14, 2026 Source: Vendor

Imported by the Apple release catcher from https://support.apple.com/en-us/149034. 126 CVE entries, 67 additional recognitions. Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://support.apple.com/en-us/149034
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

378 lines
Showing 201–250 of 377 matching · page 5 of 8 · clear filters
CVE-2026-84621 BR2026-0000-012427 Spotlight unclaimed
An app may be able to access sensitive user data
Credited as Ujjwal Reddy Kalvolu Sreenivasa Reddy
CVE-2026-84621 BR2026-0000-012428 Spotlight unclaimed
An app may be able to access sensitive user data
Credited as Johan Wahyudi
CVE-2026-86892 BR2026-0000-012429 SpringBoard unclaimed
An app may be able to cause a denial-of-service
Credited as Lehan Dilusha Jayasingha
CVE-2026-65348 BR2026-0000-012430 Storage unclaimed
An app may be able to modify protected parts of the file system
Credited as Jérôme Djouder
CVE-2026-65345 BR2026-0000-012431 Storage unclaimed
An app may be able to access user-sensitive data
Credited as Seung Je Seong
CVE-2026-65345 BR2026-0000-012432 Storage unclaimed
An app may be able to access user-sensitive data
Credited as Ilya Andr (andrd3v) of Positive Technologies
CVE-2026-65345 BR2026-0000-012433 Storage unclaimed
An app may be able to access user-sensitive data
Credited as Jakob Pammer
CVE-2026-65345 BR2026-0000-012434 Storage unclaimed
An app may be able to access user-sensitive data
Credited as 이재영
CVE-2026-84513 BR2026-0000-012435 Symptom Framework unclaimed
A malicious application may be able to determine a user's current location
Credited as Sindre Sorhus
CVE-2026-86886 BR2026-0000-012436 TCC unclaimed
An app may be able to modify protected system files
Credited as Constantin Clerc
CVE-2026-86886 BR2026-0000-012437 TCC unclaimed
An app may be able to modify protected system files
Credited as Shad J
CVE-2026-86886 BR2026-0000-012438 TCC unclaimed
An app may be able to modify protected system files
Credited as huami1314 (@huamidev)
CVE-2026-86886 BR2026-0000-012439 TCC unclaimed
An app may be able to modify protected system files
Credited as Huy Nguyen (@34306) of Calif.io
CVE-2026-84527 BR2026-0000-012440 TCC unclaimed
An app may be able to access sensitive user data
Credited as Zeyang Li&Yuxiang Wang of Chongqing Telecom
CVE-2026-65329 BR2026-0000-012441 Telephony unclaimed
An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic
Credited as Bedran Karakoc
CVE-2026-65329 BR2026-0000-012442 Telephony unclaimed
An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic
Credited as Tobias Funke
CVE-2026-65329 BR2026-0000-012443 Telephony unclaimed
An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic
Credited as Jacopo Clark
CVE-2026-65329 BR2026-0000-012444 Telephony unclaimed
An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic
Credited as Katharina Kohls of Ruhr University Bochum
CVE-2026-86904 BR2026-0000-012445 Watch App unclaimed
An app may be able to track users across apps and websites without permission
Credited as Stanislav Jelezoglo
CVE-2026-84635 BR2026-0000-012446 WebKit unclaimed
Processing maliciously crafted web content may lead to an unexpected process termination
Credited as Souta Sugiyama
CVE-2026-64753 BR2026-0000-012447 WebKit unclaimed
Processing maliciously crafted web content may disclose sensitive user information
Credited as Viggo Lekdorf
CVE-2026-86898 BR2026-0000-012448 WebKit unclaimed
Opening a maliciously crafted webarchive file may lead to universal cross-site scripting
Credited as Tomi Garcia (archyxsec)
CVE-2026-64718 BR2026-0000-012449 WebKit Canvas unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Niels Hofmans
CVE-2026-64718 BR2026-0000-012450 WebKit Canvas unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as OGINOME Tomohito
CVE-2026-43674 BR2026-0000-012451 Wi-Fi3 unclaimed
An attacker with physical access to an unlocked device may be able to view Wi-Fi passwords without authentication
Credited as Yusuf Kelany
CVE-2026-84636 BR2026-0000-012452 Wi-Fi Connectivity unclaimed
An app may be able to access sensitive user data
Credited as Jian Lee (@speedyfriend433)
CVE-2026-84617 BR2026-0000-012453 XPC unclaimed
An app may be able to access sensitive user data
Credited as Stuart Wallace
Additional recognition BR2026-0000-012454 Accessibility unclaimed
Credited as Abhay Kailasia (@abhay_kailasia) from Safran Mumbai India
Additional recognition BR2026-0000-012455 Accounts unclaimed
Credited as Wojciech Regula of SecuRing (wojciechregula.blog)
Additional recognition BR2026-0000-012456 AppleKeyStore unclaimed
Credited as Abdurrahman Nafi
Additional recognition BR2026-0000-012457 AppleKeyStore unclaimed
Credited as Francisco Knabe
Additional recognition BR2026-0000-012458 AppleKeyStore unclaimed
Credited as Karol Mazurek (@Karmaz95) of AFINE
Additional recognition BR2026-0000-012459 AppleKeyStore unclaimed
Credited as Somair Ansar
Additional recognition BR2026-0000-012460 AppleKeyStore unclaimed
Credited as YOKI
Additional recognition BR2026-0000-012461 AppleKeyStore unclaimed
Credited as 晓娟 谢
Additional recognition BR2026-0000-012462 Audio unclaimed
Credited as Dhiyanesh Selvaraj (@redroot97)
Additional recognition BR2026-0000-012463 AutoFill unclaimed
Credited as Bistrit Dahal
Additional recognition BR2026-0000-012464 AutoFill unclaimed
Credited as Oussama Barbar
Additional recognition BR2026-0000-012465 AutoFill unclaimed
Credited as SalahAldeen Yousef
Additional recognition BR2026-0000-012466 AVEVideoEncoder unclaimed
Credited as tamdao
Additional recognition BR2026-0000-012467 Baseband unclaimed
Credited as Kai Tu
Additional recognition BR2026-0000-012468 Baseband unclaimed
Credited as Tianchang Yang
Additional recognition BR2026-0000-012469 Baseband unclaimed
Credited as Xiaotian Zhou
Additional recognition BR2026-0000-012470 Baseband unclaimed
Credited as Ali Ranjbar
Additional recognition BR2026-0000-012471 Baseband unclaimed
Credited as Abdullah Al Ishtiaq
Additional recognition BR2026-0000-012472 Baseband unclaimed
Credited as Tianwei Wu
Additional recognition BR2026-0000-012473 Baseband unclaimed
Credited as Yilu Dong
Additional recognition BR2026-0000-012474 Baseband unclaimed
Credited as Syed Rafiul Hussain — SyNSec Lab at Penn State
Additional recognition BR2026-0000-012475 Bluetooth unclaimed
Credited as David Maynor
Additional recognition BR2026-0000-012476 Bluetooth unclaimed
Credited as Jason Grove