Early access: this site has moved to bugrater.com.

Security releases

Apple

macOS Golden Gate 27

149035 Sep 14, 2026 Source: Vendor

Imported by the Apple release catcher from https://support.apple.com/en-us/149035. 210 CVE entries, 75 additional recognitions. Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020 and later), MacBook Pro with Apple silicon (2020 and later), iMac with Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and later), Mac Studio (2022 and later), and Mac Pro with Apple silicon (2023). Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://support.apple.com/en-us/149035
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

555 lines
Showing 351–400 of 555 · page 8 of 12
CVE-2026-86909 BR2026-0000-013125 System Settings unclaimed
An app may be able to bypass Gatekeeper checks
Credited as Koh M. Nakagawa (@tsunek0h) of FFRI Security, Inc.
CVE-2026-84527 BR2026-0000-013126 TCC unclaimed
An app may be able to access sensitive user data
Credited as Zeyang Li&Yuxiang Wang of Chongqing Telecom
CVE-2026-84589 BR2026-0000-013127 TCC unclaimed
An app may be able to modify Privacy preferences
Credited as Rodolphe Brunetti (@eisw0lf)
CVE-2026-84589 BR2026-0000-013128 TCC unclaimed
An app may be able to modify Privacy preferences
Credited as Ryan Dowd (@_rdowd)
CVE-2026-84589 BR2026-0000-013129 TCC unclaimed
An app may be able to modify Privacy preferences
Credited as Isaiah Ryan Ehlert (isaiahehlert@icloud.com)
CVE-2026-84589 BR2026-0000-013130 TCC unclaimed
An app may be able to modify Privacy preferences
Credited as Csaba Fitzl (@theevilbit) of Iru
CVE-2026-28937 BR2026-0000-013131 Terminal unclaimed
An app may be able to access sensitive user data
Credited as Charlie Weiss
CVE-2026-28937 BR2026-0000-013132 Terminal unclaimed
An app may be able to access sensitive user data
Credited as Noah Gregory (wts.dev)
CVE-2026-84572 BR2026-0000-013133 udf unclaimed
An app may be able to cause unexpected system termination or read kernel memory
Credited as Tomi (tk0) Koski (@tomikoski)
CVE-2026-84572 BR2026-0000-013134 udf unclaimed
An app may be able to cause unexpected system termination or read kernel memory
Credited as Hari Shanmugam (The Hxr1)
CVE-2026-84506 BR2026-0000-013135 udf unclaimed
An app may be able to execute arbitrary code with kernel privileges
Credited as Billy Jheng Bing Jhong
CVE-2026-84506 BR2026-0000-013136 udf unclaimed
An app may be able to execute arbitrary code with kernel privileges
Credited as Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.
CVE-2026-28899 BR2026-0000-013137 WebDAV unclaimed
An app may bypass Gatekeeper checks
Credited as Andreas Jaegersberger
CVE-2026-28899 BR2026-0000-013138 WebDAV unclaimed
An app may bypass Gatekeeper checks
Credited as Ro Achterberg of Nosebeard Labs
CVE-2026-28899 BR2026-0000-013139 WebDAV unclaimed
An app may bypass Gatekeeper checks
Credited as Kraken Cryptocurrency Exchange
CVE-2026-65374 BR2026-0000-013140 WebDAV unclaimed
Connecting to a malicious WebDAV server may result in code execution
Credited as HE WEI(ギカク)
CVE-2026-65374 BR2026-0000-013141 WebDAV unclaimed
Connecting to a malicious WebDAV server may result in code execution
Credited as Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-65375 BR2026-0000-013142 WebDAV unclaimed
An app may be able to cause unexpected system termination
Credited as YingMuo (@YingMuo) of DEVCORE Research Team
CVE-2026-65375 BR2026-0000-013143 WebDAV unclaimed
An app may be able to cause unexpected system termination
Credited as Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-43677 BR2026-0000-013144 WebDAV unclaimed
Connecting to a malicious WebDAV server may lead to unexpected app termination
Credited as bubu
CVE-2026-43677 BR2026-0000-013145 WebDAV unclaimed
Connecting to a malicious WebDAV server may lead to unexpected app termination
Credited as Omar Cerrito
CVE-2026-43677 BR2026-0000-013146 WebDAV unclaimed
Connecting to a malicious WebDAV server may lead to unexpected app termination
Credited as HE WEI(ギカク)
CVE-2026-43677 BR2026-0000-013147 WebDAV unclaimed
Connecting to a malicious WebDAV server may lead to unexpected app termination
Credited as Roman Zabicki
CVE-2026-43677 BR2026-0000-013148 WebDAV unclaimed
Connecting to a malicious WebDAV server may lead to unexpected app termination
Credited as Richard Zana
CVE-2026-43677 BR2026-0000-013149 WebDAV unclaimed
Connecting to a malicious WebDAV server may lead to unexpected app termination
Credited as Chris Bailey - Short Circuit
CVE-2026-43677 BR2026-0000-013150 WebDAV unclaimed
Connecting to a malicious WebDAV server may lead to unexpected app termination
Credited as Aswin Kumar Gokulakannan
CVE-2026-43677 BR2026-0000-013151 WebDAV unclaimed
Connecting to a malicious WebDAV server may lead to unexpected app termination
Credited as Surya Narayan Kushwaha
CVE-2026-43677 BR2026-0000-013152 WebDAV unclaimed
Connecting to a malicious WebDAV server may lead to unexpected app termination
Credited as Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-84635 BR2026-0000-013153 WebKit unclaimed
Processing maliciously crafted web content may lead to an unexpected process termination
Credited as Souta Sugiyama
CVE-2026-64753 BR2026-0000-013154 WebKit unclaimed
Processing maliciously crafted web content may disclose sensitive user information
Credited as Viggo Lekdorf
CVE-2026-86898 BR2026-0000-013155 WebKit unclaimed
Opening a maliciously crafted webarchive file may lead to universal cross-site scripting
Credited as Tomi Garcia (archyxsec)
CVE-2026-64718 BR2026-0000-013156 WebKit Canvas unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Niels Hofmans
CVE-2026-64718 BR2026-0000-013157 WebKit Canvas unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as OGINOME Tomohito
CVE-2026-65393 BR2026-0000-013158 Xcode IDE unclaimed
An app may be able to access user-sensitive data
Credited as Mickey Jin (@patch1t)
CVE-2026-84617 BR2026-0000-013159 XPC unclaimed
An app may be able to access sensitive user data
Credited as Stuart Wallace
Additional recognition BR2026-0000-013160 Accounts unclaimed
Credited as Wojciech Regula of SecuRing (wojciechregula.blog)
Additional recognition BR2026-0000-013161 adv_cmds unclaimed
Credited as Franco Belman at Blackwing Intelligence
Additional recognition BR2026-0000-013162 AirPort unclaimed
Credited as Arni Hardarson (Neonix Security)
Additional recognition BR2026-0000-013163 AirPort unclaimed
Credited as Christian Figueroa
Additional recognition BR2026-0000-013164 AirPort unclaimed
Credited as Dhiyanesh Selvaraj (@redroot97)
Additional recognition BR2026-0000-013165 AirPort unclaimed
Credited as Harish Santhanalakshmi Ganesan of Cisco AI Defense and a member of Cisco Talos
Additional recognition BR2026-0000-013166 AirPort unclaimed
Credited as Niels Hofmans
Additional recognition BR2026-0000-013167 AirPort unclaimed
Credited as Robert Mindo
Additional recognition BR2026-0000-013168 AirPort unclaimed
Credited as Tae Woo Kim (CYTUR)
Additional recognition BR2026-0000-013169 APFS unclaimed
Credited as Nick Max
Additional recognition BR2026-0000-013170 APFS unclaimed
Credited as Ruslan Dautov
Additional recognition BR2026-0000-013171 App Intents unclaimed
Credited as Adetayo Adebimpe
Additional recognition BR2026-0000-013172 Apple Account unclaimed
Credited as 糖豆爸爸(@晴天组织)
Additional recognition BR2026-0000-013173 Apple Online Store Kit unclaimed
Credited as Pietro Francesco Tirenna (shielder.com)
Additional recognition BR2026-0000-013174 Apple Online Store Kit unclaimed
Credited as Zhongcheng Li (CK01)