Apple
macOS Golden Gate 27
149035 Sep 14, 2026 Source: Vendor
Imported by the Apple release catcher from https://support.apple.com/en-us/149035. 210 CVE entries, 75 additional recognitions. Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020 and later), MacBook Pro with Apple silicon (2020 and later), iMac with Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and later), Mac Studio (2022 and later), and Mac Pro with Apple silicon (2023). Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://support.apple.com/en-us/149035
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
555 lines
Showing 301–350 of 555 · page 7 of 12
CVE-2026-86881
BR2026-0000-013075
Security
unclaimed
An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages
Credited as Surya Narayan Kushwaha
CVE-2026-86881
BR2026-0000-013076
Security
unclaimed
An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages
Credited as Roman Zabicki
CVE-2026-86881
BR2026-0000-013077
Security
unclaimed
An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages
Credited as John Lussier
CVE-2026-86881
BR2026-0000-013078
Security
unclaimed
An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages
Credited as Filip Olszak
CVE-2026-84531
BR2026-0000-013079
Security
unclaimed
Processing maliciously crafted NTLM input may lead to unexpected app termination
Credited as Meshaal (@unrealmesh)
CVE-2026-84600
BR2026-0000-013080
Shortcuts
unclaimed
A malicious shortcut may be able to send messages without user confirmation
Credited as Owen Pawling (@owenpawling)
CVE-2026-86884
BR2026-0000-013081
Siri
unclaimed
An app may be able to access sensitive user data
Credited as Stanislav Jelezoglo
CVE-2026-86884
BR2026-0000-013082
Siri
unclaimed
An app may be able to access sensitive user data
Credited as Gongyu Ma (twitter @Mezone0)
CVE-2026-43690
BR2026-0000-013083
SMB
unclaimed
A local user may be able to read kernel memory
Credited as Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-43719
BR2026-0000-013084
SMB
unclaimed
Mounting a maliciously crafted SMB network share may lead to system termination
Credited as Jakob Pammer
CVE-2026-43719
BR2026-0000-013085
SMB
unclaimed
Mounting a maliciously crafted SMB network share may lead to system termination
Credited as Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-65376
BR2026-0000-013086
SMB
unclaimed
An app may be able to cause unexpected system termination
Credited as 재영 정
CVE-2026-65376
BR2026-0000-013087
SMB
unclaimed
An app may be able to cause unexpected system termination
Credited as Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-84543
BR2026-0000-013088
SMB
unclaimed
Connecting to a malicious SMB server may cause unexpected system termination or corrupt kernel memory
Credited as Peter Malone
CVE-2026-84537
BR2026-0000-013089
SMB
unclaimed
An app may be able to cause unexpected system termination or corrupt kernel memory
Credited as Feng Xue
CVE-2026-84537
BR2026-0000-013090
SMB
unclaimed
An app may be able to cause unexpected system termination or corrupt kernel memory
Credited as XGPT of ThreatBook
CVE-2026-84537
BR2026-0000-013091
SMB
unclaimed
An app may be able to cause unexpected system termination or corrupt kernel memory
Credited as Peter Malone
CVE-2026-84536
BR2026-0000-013092
SMB
unclaimed
Connecting to a malicious SMB server may lead to unexpected system termination
Credited as 재영 정
CVE-2026-84536
BR2026-0000-013093
SMB
unclaimed
Connecting to a malicious SMB server may lead to unexpected system termination
Credited as Feng Xue
CVE-2026-84536
BR2026-0000-013094
SMB
unclaimed
Connecting to a malicious SMB server may lead to unexpected system termination
Credited as XGPT of ThreatBook
CVE-2026-84536
BR2026-0000-013095
SMB
unclaimed
Connecting to a malicious SMB server may lead to unexpected system termination
Credited as Peter Malone
CVE-2026-65365
BR2026-0000-013096
SMB
unclaimed
Connecting to a malicious SMB share may disclose kernel memory
Credited as Jay Patel
CVE-2026-65365
BR2026-0000-013097
SMB
unclaimed
Connecting to a malicious SMB share may disclose kernel memory
Credited as Peter Malone
CVE-2026-84515
BR2026-0000-013098
SMB
unclaimed
Connecting to a malicious SMB server may lead to kernel memory corruption
Credited as 재영 정
CVE-2026-84515
BR2026-0000-013099
SMB
unclaimed
Connecting to a malicious SMB server may lead to kernel memory corruption
Credited as Peter Malone
CVE-2026-84509
BR2026-0000-013100
SMB
unclaimed
Connecting to a malicious SMB server may lead to unexpected system termination
Credited as Dave G.
CVE-2026-84553
BR2026-0000-013101
smbx
unclaimed
A remote attacker may be able to cause a denial-of-service
Credited as Stuart Thomas
CVE-2026-84609
BR2026-0000-013102
Software Update
unclaimed
An app may be able to modify protected system files
Credited as YingMuo (@YingMuo) of DEVCORE Research Team
CVE-2026-65361
BR2026-0000-013103
SoftwareUpdate
unclaimed
An app may be able to access sensitive user data
Credited as Rodolphe BRUNETTI (@eisw0lf) of Lupus Nova
CVE-2026-65378
BR2026-0000-013104
Spotlight
unclaimed
An app may be able to access sensitive user data
Credited as Abodi Dawoud
CVE-2026-65378
BR2026-0000-013105
Spotlight
unclaimed
An app may be able to access sensitive user data
Credited as Sindre Sorhus
CVE-2026-65378
BR2026-0000-013106
Spotlight
unclaimed
An app may be able to access sensitive user data
Credited as 糖豆爸爸(@晴天组织)
CVE-2026-65378
BR2026-0000-013107
Spotlight
unclaimed
An app may be able to access sensitive user data
Credited as Niels Hofmans
CVE-2026-65378
BR2026-0000-013108
Spotlight
unclaimed
An app may be able to access sensitive user data
Credited as Robert Mindo
CVE-2026-84621
BR2026-0000-013109
Spotlight
unclaimed
An app may be able to access sensitive user data
Credited as Abodi Dawoud
CVE-2026-84621
BR2026-0000-013110
Spotlight
unclaimed
An app may be able to access sensitive user data
Credited as Armend Gashi
CVE-2026-84621
BR2026-0000-013111
Spotlight
unclaimed
An app may be able to access sensitive user data
Credited as Ujjwal Reddy Kalvolu Sreenivasa Reddy
CVE-2026-84621
BR2026-0000-013112
Spotlight
unclaimed
An app may be able to access sensitive user data
Credited as Johan Wahyudi
CVE-2026-43788
BR2026-0000-013113
Spotlight
unclaimed
Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents
Credited as Narendra Singh (@_3P1C)
CVE-2026-43788
BR2026-0000-013114
Spotlight
unclaimed
Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents
Credited as Ashish Kunwar
CVE-2026-65348
BR2026-0000-013115
Storage
unclaimed
An app may be able to modify protected parts of the file system
Credited as Jérôme Djouder
CVE-2026-65345
BR2026-0000-013116
Storage
unclaimed
An app may be able to access user-sensitive data
Credited as Seung Je Seong
CVE-2026-65345
BR2026-0000-013117
Storage
unclaimed
An app may be able to access user-sensitive data
Credited as Ilya Andr (andrd3v) of Positive Technologies
CVE-2026-65345
BR2026-0000-013118
Storage
unclaimed
An app may be able to access user-sensitive data
Credited as Jakob Pammer
CVE-2026-65345
BR2026-0000-013119
Storage
unclaimed
An app may be able to access user-sensitive data
Credited as 이재영
CVE-2026-43791
BR2026-0000-013120
StorageKit
unclaimed
An app may be able to read arbitrary files
Credited as Meridian Miftari
CVE-2026-43791
BR2026-0000-013121
StorageKit
unclaimed
An app may be able to read arbitrary files
Credited as Amy (amys.website)
CVE-2026-43791
BR2026-0000-013122
StorageKit
unclaimed
An app may be able to read arbitrary files
Credited as Aaron Grattafiori - NVIDIA AI Red Team
CVE-2026-84513
BR2026-0000-013123
Symptom Framework
unclaimed
A malicious application may be able to determine a user's current location
Credited as Sindre Sorhus
CVE-2026-65383
BR2026-0000-013124
System Settings
unclaimed
An app may bypass Gatekeeper checks
Credited as Zhongquan Li (@Guluisacat)