Early access: this site has moved to bugrater.com.

Security releases

Apple

macOS Golden Gate 27

149035 Sep 14, 2026 Source: Vendor

Imported by the Apple release catcher from https://support.apple.com/en-us/149035. 210 CVE entries, 75 additional recognitions. Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020 and later), MacBook Pro with Apple silicon (2020 and later), iMac with Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and later), Mac Studio (2022 and later), and Mac Pro with Apple silicon (2023). Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://support.apple.com/en-us/149035
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

555 lines
Showing 251–300 of 385 matching · page 6 of 8 · clear filters
CVE-2026-43787 BR2026-0000-013025 Mail unclaimed
An attacker in a privileged network position may be able to leak sensitive user information
Credited as Armend Gashi
CVE-2026-84628 BR2026-0000-013026 MediaRemote unclaimed
A sandboxed app may be able to access the System Keychain
Credited as Myeonghun Pak
CVE-2026-84628 BR2026-0000-013027 MediaRemote unclaimed
A sandboxed app may be able to access the System Keychain
Credited as Nathaniel Oh (@calysteon)
CVE-2026-84628 BR2026-0000-013028 MediaRemote unclaimed
A sandboxed app may be able to access the System Keychain
Credited as Alan Banderas (@creeper4004)
CVE-2026-43741 BR2026-0000-013029 Messages unclaimed
An app may be able to access protected user data
Credited as Dawuge of Shuffle Team
CVE-2026-86924 BR2026-0000-013030 MobileAccessoryUpdater unclaimed
Connecting a malicious accessory may cause unexpected system termination
Credited as Matthew Zamat
CVE-2026-84497 BR2026-0000-013031 Model I/O unclaimed
Opening a maliciously crafted file may lead to unexpected process termination
Credited as Yiğit Can YILMAZ (@yilmazcanyigit)
CVE-2026-84585 BR2026-0000-013032 NetworkExtension unclaimed
An app may be able to access local network devices without user consent
Credited as Dmytro Merkulov
CVE-2026-43695 BR2026-0000-013033 NetworkExtension unclaimed
An app may be able to access sensitive user data
Credited as Claudio Bozzato
CVE-2026-43695 BR2026-0000-013034 NetworkExtension unclaimed
An app may be able to access sensitive user data
Credited as Francesco Benvenuto of Cisco Talos
CVE-2026-84626 BR2026-0000-013035 NetworkExtension unclaimed
An app may be able to identify what other apps a user has installed
Credited as Sindre Sorhus
CVE-2026-84626 BR2026-0000-013036 NetworkExtension unclaimed
An app may be able to identify what other apps a user has installed
Credited as Hoffcona of IES Red Team
CVE-2026-86902 BR2026-0000-013037 NSDocument unclaimed
An app may be able to access sensitive user data
Credited as silo
CVE-2026-64712 BR2026-0000-013038 odproxyd unclaimed
An app may be able to gain root privileges
Credited as Andreas Jaegersberger
CVE-2026-64712 BR2026-0000-013039 odproxyd unclaimed
An app may be able to gain root privileges
Credited as Ro Achterberg of Nosebeard Labs
CVE-2026-84578 BR2026-0000-013040 quarantine unclaimed
An app may be able to break out of its sandbox
Credited as Kenneth Chew
CVE-2026-84576 BR2026-0000-013041 QuartzCore unclaimed
An app may be able to access sensitive user data
Credited as Dora Orak
CVE-2026-84576 BR2026-0000-013042 QuartzCore unclaimed
An app may be able to access sensitive user data
Credited as @Ethan Arbuckle
CVE-2026-84576 BR2026-0000-013043 QuartzCore unclaimed
An app may be able to access sensitive user data
Credited as and @leptos_null
CVE-2026-84548 BR2026-0000-013044 Quick Look unclaimed
Processing a maliciously crafted document may lead to an out-of-bounds read
Credited as Peter Malone
CVE-2026-28966 BR2026-0000-013045 RealityKit unclaimed
Processing a maliciously crafted file may lead to unexpected app termination
Credited as stratan (@5tratan)
CVE-2026-84532 BR2026-0000-013046 RealityKit unclaimed
Opening a maliciously crafted file may cause unexpected process termination or disclose process memory
Credited as Hongsik Kim (mnur)
CVE-2026-84532 BR2026-0000-013047 RealityKit unclaimed
Opening a maliciously crafted file may cause unexpected process termination or disclose process memory
Credited as stratan (@5tratan)
CVE-2026-65403 BR2026-0000-013048 Reminders unclaimed
An app may be able to access sensitive user data
Credited as Rahul Raj
CVE-2026-84518 BR2026-0000-013049 Safari unclaimed
A malicious website may be able to determine what apps a user has installed
Credited as Bálint Magyar (balintmagyar.com)
CVE-2026-86897 BR2026-0000-013050 Safe Browsing unclaimed
An app may be able to access sensitive user data
Credited as Stuart Wallace
CVE-2026-65380 BR2026-0000-013051 Sandbox unclaimed
An app may be able to access protected user data
Credited as Kieran Klukas (taciturnaxolotl)
CVE-2026-84555 BR2026-0000-013052 Sandbox unclaimed
An app may be able to access sensitive user data
Credited as Liu Xue
CVE-2026-84555 BR2026-0000-013053 Sandbox unclaimed
An app may be able to access sensitive user data
Credited as 九宫格 of Chongqing Telecom
CVE-2026-84551 BR2026-0000-013054 Sandbox unclaimed
An app may be able to bypass network restrictions
Credited as Issa Sancho
CVE-2026-84625 BR2026-0000-013055 Sandbox Profiles unclaimed
An app may be able to fingerprint the user
Credited as Ilya Andr (andrd3v) of Positive Technologies
CVE-2026-84625 BR2026-0000-013056 Sandbox Profiles unclaimed
An app may be able to fingerprint the user
Credited as CJ Vana
CVE-2026-43697 BR2026-0000-013057 SceneKit unclaimed
Processing a maliciously crafted 3D file may lead to an out-of-bounds read
Credited as Peter Malone
CVE-2026-84487 BR2026-0000-013058 SceneKit unclaimed
Processing a maliciously crafted file may result in disclosure of process memory
Credited as stratan (@5tratan)
CVE-2026-84487 BR2026-0000-013059 SceneKit unclaimed
Processing a maliciously crafted file may result in disclosure of process memory
Credited as Dhiyanesh Selvaraj (@redroot97)
CVE-2026-84487 BR2026-0000-013060 SceneKit unclaimed
Processing a maliciously crafted file may result in disclosure of process memory
Credited as Peter Malone
CVE-2026-65413 BR2026-0000-013061 SceneKit unclaimed
An app may be able to cause a denial of service
Credited as Peter Malone
CVE-2026-84632 BR2026-0000-013062 SceneKit unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as Peter Malone
CVE-2026-84620 BR2026-0000-013063 SceneKit unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as Peter Malone
CVE-2026-84546 BR2026-0000-013064 SceneKit unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as Narendra Singh (@_3P1C)
CVE-2026-84546 BR2026-0000-013065 SceneKit unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as stratan (@5tratan)
CVE-2026-84546 BR2026-0000-013066 SceneKit unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as Peter Malone
CVE-2026-84611 BR2026-0000-013067 SceneKit unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as Nathaniel Oh (@calysteon)
CVE-2026-84526 BR2026-0000-013068 SceneKit unclaimed
Processing a maliciously crafted 3D scene may lead to unexpected process termination
Credited as stratan (@5tratan)
CVE-2026-65400 BR2026-0000-013069 Screen Sharing Server unclaimed
An attacker on the network may be able to authenticate to Screen Sharing without valid credentials
Credited as Alfredo Pesoli (@__rev) via Bynario Atlas (bynar.io)
CVE-2026-86889 BR2026-0000-013070 Security unclaimed
An attacker in a privileged network position may be able to intercept network traffic
Credited as Jaeho Nam
CVE-2026-86889 BR2026-0000-013071 Security unclaimed
An attacker in a privileged network position may be able to intercept network traffic
Credited as Jungbum Lee
CVE-2026-86889 BR2026-0000-013072 Security unclaimed
An attacker in a privileged network position may be able to intercept network traffic
Credited as Sangwi Kang
CVE-2026-86889 BR2026-0000-013073 Security unclaimed
An attacker in a privileged network position may be able to intercept network traffic
Credited as Hyeonguk Ko
CVE-2026-86889 BR2026-0000-013074 Security unclaimed
An attacker in a privileged network position may be able to intercept network traffic
Credited as Taekyoung Kwon from SNU CSE MMLAB (mmlab.snu.ac.kr)