Early access: this site has moved to bugrater.com.

Security releases

Apple

macOS Tahoe 26.5

127115 May 11, 2026 Source: Vendor

Imported by the Apple release catcher (re-scrape) from https://support.apple.com/en-us/127115. 87 CVE entries, 30 additional recognitions. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://support.apple.com/en-us/127115
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

189 lines
Showing 51–100 of 189 · page 2 of 4
CVE-2026-28972 BR2026-0000-009339 Kernel unclaimed
An app may be able to cause unexpected system termination or write kernel memory
Credited as Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.
CVE-2026-28972 BR2026-0000-009340 Kernel unclaimed
An app may be able to cause unexpected system termination or write kernel memory
Credited as Ryan Hileman via Xint Code (xint.io)
CVE-2026-28986 BR2026-0000-009341 Kernel unclaimed
An app may be able to cause unexpected system termination
Credited as Chris Betz
CVE-2026-28986 BR2026-0000-009342 Kernel unclaimed
An app may be able to cause unexpected system termination
Credited as Tristan Madani (@TristanInSec) from Talence Security
CVE-2026-28986 BR2026-0000-009343 Kernel unclaimed
An app may be able to cause unexpected system termination
Credited as Ryan Hileman via Xint Code (xint.io)
CVE-2026-28987 BR2026-0000-009344 Kernel unclaimed
An app may be able to leak sensitive kernel state
Credited as Dhiyanesh Selvaraj (@redroot97)
CVE-2026-28983 BR2026-0000-009345 LaunchServices unclaimed
A remote attacker may be able to cause a denial of service
Credited as Ruslan Dautov
CVE-2026-28900 BR2026-0000-009346 libarchive unclaimed
A maliciously crafted ZIP archive may bypass Gatekeeper checks
Credited as Prathamesh Walunj (@attahasa)
CVE-2026-28929 BR2026-0000-009347 Mail Drafts unclaimed
Replying to an email could display remote images in Mail in Lockdown Mode
Credited as Yiğit Can YILMAZ (@yilmazcanyigit)
CVE-2026-43653 BR2026-0000-009348 mDNSResponder unclaimed
An attacker on the local network may be able to cause a denial-of-service
Credited as Atul R V
CVE-2026-28985 BR2026-0000-009349 mDNSResponder unclaimed
An attacker on the local network may be able to cause a denial-of-service
Credited as Omar Cerrito
CVE-2026-43668 BR2026-0000-009350 mDNSResponder unclaimed
A remote attacker may be able to cause unexpected system termination or corrupt kernel memory
Credited as Anton Pakhunov
CVE-2026-43668 BR2026-0000-009351 mDNSResponder unclaimed
A remote attacker may be able to cause unexpected system termination or corrupt kernel memory
Credited as Ricardo Prado
CVE-2026-43666 BR2026-0000-009352 mDNSResponder unclaimed
An attacker on the local network may be able to cause a denial-of-service
Credited as Ian van der Wurff (ian.nl)
CVE-2026-28941 BR2026-0000-009353 Model I/O unclaimed
Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents
Credited as Michael DePlante (@izobashi) of TrendAI Zero Day Initiative
CVE-2026-28940 BR2026-0000-009354 Model I/O unclaimed
Processing a maliciously crafted image may corrupt process memory
Credited as Michael DePlante (@izobashi) of TrendAI Zero Day Initiative
CVE-2026-28961 BR2026-0000-009355 Network Extensions unclaimed
An attacker with physical access to a locked device may be able to view sensitive user information
Credited as Dan Raviv
CVE-2026-28906 BR2026-0000-009356 Networking unclaimed
An attacker may be able to track users through their IP address
Credited as Ilya Sc. Jowell A.
CVE-2026-43656 BR2026-0000-009357 Quick Look unclaimed
Parsing a maliciously crafted file may lead to an unexpected app termination
Credited as Peter Malone
CVE-2026-43652 BR2026-0000-009358 Sandbox unclaimed
An app may be able to access protected user data
Credited as Asaf Cohen
CVE-2026-39870 BR2026-0000-009359 SceneKit unclaimed
Processing a maliciously crafted image may corrupt process memory
Credited as Peter Malone
CVE-2026-28846 BR2026-0000-009360 SceneKit unclaimed
A remote attacker may be able to cause unexpected app termination
Credited as Peter Malone
CVE-2026-28993 BR2026-0000-009361 Shortcuts unclaimed
An app may be able to access user-sensitive data
Credited as Doron Assness
CVE-2026-28848 BR2026-0000-009362 SMB unclaimed
A remote attacker may be able to cause unexpected system termination
Credited as Surya Kushwaha
CVE-2026-28848 BR2026-0000-009363 SMB unclaimed
A remote attacker may be able to cause unexpected system termination
Credited as Robert Tran
CVE-2026-28848 BR2026-0000-009364 SMB unclaimed
A remote attacker may be able to cause unexpected system termination
Credited as Peter Malone
CVE-2026-28848 BR2026-0000-009365 SMB unclaimed
A remote attacker may be able to cause unexpected system termination
Credited as Dave G.
CVE-2026-28848 BR2026-0000-009366 SMB unclaimed
A remote attacker may be able to cause unexpected system termination
Credited as Alex Radocea of Supernetworks
CVE-2026-28930 BR2026-0000-009367 Spotlight unclaimed
An app may be able to access protected user data
Credited as Pan ZhenPeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.
CVE-2026-28974 BR2026-0000-009368 Spotlight unclaimed
An app may be able to cause a denial-of-service
Credited as Andy Koo (@andykoo) of Hexens
CVE-2026-28996 BR2026-0000-009369 Storage unclaimed
An app may be able to access sensitive user data
Credited as Alex Radocea
CVE-2026-28919 BR2026-0000-009370 StorageKit unclaimed
An app may be able to gain root privileges
Credited as Amy (amys.website)
CVE-2026-28924 BR2026-0000-009371 Sync Services unclaimed
An app may be able to access Contacts without user consent
Credited as Andreas Jaegersberger
CVE-2026-28924 BR2026-0000-009372 Sync Services unclaimed
An app may be able to access Contacts without user consent
Credited as Ro Achterberg of Nosebeard Labs
CVE-2026-28924 BR2026-0000-009373 Sync Services unclaimed
An app may be able to access Contacts without user consent
Credited as YingQi Shi (@Mas0nShi) of DBAppSecurity's WeBin lab
CVE-2026-28976 BR2026-0000-009374 UserAccountUpdater unclaimed
An app may be able to gain root privileges
Credited as David Ige - Beryllium Security
CVE-2026-43660 BR2026-0000-009375 WebKit unclaimed
Processing maliciously crafted web content may prevent Content Security Policy from being enforced
Credited as Cantina
CVE-2026-28907 BR2026-0000-009376 WebKit unclaimed
Processing maliciously crafted web content may prevent Content Security Policy from being enforced
Credited as Cantina
CVE-2026-28962 BR2026-0000-009377 WebKit unclaimed
Processing maliciously crafted web content may disclose sensitive user information
Credited as Luke Francis
CVE-2026-28962 BR2026-0000-009378 WebKit unclaimed
Processing maliciously crafted web content may disclose sensitive user information
Credited as Vaagn Vardanian
CVE-2026-28962 BR2026-0000-009379 WebKit unclaimed
Processing maliciously crafted web content may disclose sensitive user information
Credited as kwak kiyong / kakaogames
CVE-2026-28962 BR2026-0000-009380 WebKit unclaimed
Processing maliciously crafted web content may disclose sensitive user information
Credited as Vitaly Simonovich
CVE-2026-28962 BR2026-0000-009381 WebKit unclaimed
Processing maliciously crafted web content may disclose sensitive user information
Credited as Adel Bouachraoui
CVE-2026-28962 BR2026-0000-009382 WebKit unclaimed
Processing maliciously crafted web content may disclose sensitive user information
Credited as greenbynox
CVE-2026-43658 BR2026-0000-009383 WebKit unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Do Young Park
CVE-2026-28984 BR2026-0000-009384 WebKit unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Artem Dinaburg of Trail of Bits via Anthropic CVD
CVE-2026-28905 BR2026-0000-009385 WebKit unclaimed
Processing maliciously crafted web content may lead to an unexpected process crash
Credited as Yuhao Hu
CVE-2026-28905 BR2026-0000-009386 WebKit unclaimed
Processing maliciously crafted web content may lead to an unexpected process crash
Credited as Yuanming Lai
CVE-2026-28905 BR2026-0000-009387 WebKit unclaimed
Processing maliciously crafted web content may lead to an unexpected process crash
Credited as Chenggang Wu
CVE-2026-28905 BR2026-0000-009388 WebKit unclaimed
Processing maliciously crafted web content may lead to an unexpected process crash
Credited as and Zhe Wang