Apple
macOS Tahoe 26.7
149042 Sep 14, 2026 Source: Vendor
Imported by the Apple release catcher from https://support.apple.com/en-us/149042. 154 CVE entries, 12 additional recognitions. Available for: macOS Tahoe. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://support.apple.com/en-us/149042
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
315 lines
Showing 201–250 of 315 · page 5 of 7
CVE-2026-43741
BR2026-0000-013569
Messages
unclaimed
An app may be able to access protected user data
Credited as Dawuge of Shuffle Team
CVE-2026-86924
BR2026-0000-013570
MobileAccessoryUpdater
unclaimed
Connecting a malicious accessory may cause unexpected system termination
Credited as Matthew Zamat
CVE-2026-84497
BR2026-0000-013571
Model I/O
unclaimed
Opening a maliciously crafted file may lead to unexpected process termination
Credited as Yiğit Can YILMAZ (@yilmazcanyigit)
CVE-2026-84626
BR2026-0000-013572
NetworkExtension
unclaimed
An app may be able to identify what other apps a user has installed
Credited as Sindre Sorhus
CVE-2026-84626
BR2026-0000-013573
NetworkExtension
unclaimed
An app may be able to identify what other apps a user has installed
Credited as Hoffcona of IES Red Team
CVE-2026-43695
BR2026-0000-013574
NetworkExtension
unclaimed
An app may be able to access sensitive user data
Credited as Claudio Bozzato
CVE-2026-43695
BR2026-0000-013575
NetworkExtension
unclaimed
An app may be able to access sensitive user data
Credited as Francesco Benvenuto of Cisco Talos
CVE-2026-64712
BR2026-0000-013576
odproxyd
unclaimed
An app may be able to gain root privileges
Credited as Andreas Jaegersberger
CVE-2026-64712
BR2026-0000-013577
odproxyd
unclaimed
An app may be able to gain root privileges
Credited as Ro Achterberg of Nosebeard Labs
CVE-2026-84578
BR2026-0000-013578
quarantine
unclaimed
An app may be able to break out of its sandbox
Credited as Kenneth Chew
CVE-2026-84576
BR2026-0000-013579
QuartzCore
unclaimed
An app may be able to access sensitive user data
Credited as Dora Orak
CVE-2026-84576
BR2026-0000-013580
QuartzCore
unclaimed
An app may be able to access sensitive user data
Credited as @Ethan Arbuckle
CVE-2026-84576
BR2026-0000-013581
QuartzCore
unclaimed
An app may be able to access sensitive user data
Credited as and @leptos_null
CVE-2026-84548
BR2026-0000-013582
Quick Look
unclaimed
Processing a maliciously crafted document may lead to an out-of-bounds read
Credited as Peter Malone
CVE-2026-84532
BR2026-0000-013583
RealityKit
unclaimed
Opening a maliciously crafted file may cause unexpected process termination or disclose process memory
Credited as stratan (@5tratan)
CVE-2026-84532
BR2026-0000-013584
RealityKit
unclaimed
Opening a maliciously crafted file may cause unexpected process termination or disclose process memory
Credited as Hongsik Kim (mnur)
CVE-2026-28966
BR2026-0000-013585
RealityKit
unclaimed
Processing a maliciously crafted file may lead to unexpected app termination
Credited as stratan (@5tratan)
CVE-2026-65403
BR2026-0000-013586
Reminders
unclaimed
An app may be able to access sensitive user data
Credited as Rahul Raj
CVE-2026-84487
BR2026-0000-013587
SceneKit
unclaimed
Processing a maliciously crafted file may result in disclosure of process memory
Credited as stratan (@5tratan)
CVE-2026-84487
BR2026-0000-013588
SceneKit
unclaimed
Processing a maliciously crafted file may result in disclosure of process memory
Credited as Peter Malone
CVE-2026-84487
BR2026-0000-013589
SceneKit
unclaimed
Processing a maliciously crafted file may result in disclosure of process memory
Credited as Dhiyanesh Selvaraj (@redroot97)
CVE-2026-65413
BR2026-0000-013590
SceneKit
unclaimed
An app may be able to cause a denial of service
Credited as Peter Malone
CVE-2026-84546
BR2026-0000-013591
SceneKit
unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as Narendra Singh (@_3P1C)
CVE-2026-84546
BR2026-0000-013592
SceneKit
unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as stratan (@5tratan)
CVE-2026-84546
BR2026-0000-013593
SceneKit
unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as Peter Malone
CVE-2026-84611
BR2026-0000-013594
SceneKit
unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as Nathaniel Oh (@calysteon)
CVE-2026-84632
BR2026-0000-013595
SceneKit
unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as Peter Malone
CVE-2026-84620
BR2026-0000-013596
SceneKit
unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as Peter Malone
CVE-2026-43697
BR2026-0000-013597
SceneKit
unclaimed
Processing a maliciously crafted 3D file may lead to an out-of-bounds read
Credited as Peter Malone
CVE-2026-84526
BR2026-0000-013598
SceneKit
unclaimed
Processing a maliciously crafted 3D scene may lead to unexpected process termination
Credited as stratan (@5tratan)
CVE-2026-43760
BR2026-0000-013599
Screen Sharing Server
unclaimed
An app may be able to access user-sensitive data
Credited as Alfredo Pesoli (@__rev) of Bynar.io
CVE-2026-43760
BR2026-0000-013600
Screen Sharing Server
unclaimed
An app may be able to access user-sensitive data
Credited as wdszzml
CVE-2026-43760
BR2026-0000-013601
Screen Sharing Server
unclaimed
An app may be able to access user-sensitive data
Credited as Atuin Automated Vulnerability Discovery Engine
CVE-2026-65400
BR2026-0000-013602
Screen Sharing Server
unclaimed
An attacker on the network may be able to authenticate to Screen Sharing without valid credentials
Credited as Alfredo Pesoli (@__rev) via Bynario Atlas (bynar.io)
CVE-2026-86889
BR2026-0000-013603
Security
unclaimed
An attacker in a privileged network position may be able to intercept network traffic
Credited as Jaeho Nam
CVE-2026-86889
BR2026-0000-013604
Security
unclaimed
An attacker in a privileged network position may be able to intercept network traffic
Credited as Jungbum Lee
CVE-2026-86889
BR2026-0000-013605
Security
unclaimed
An attacker in a privileged network position may be able to intercept network traffic
Credited as Sangwi Kang
CVE-2026-86889
BR2026-0000-013606
Security
unclaimed
An attacker in a privileged network position may be able to intercept network traffic
Credited as Hyeonguk Ko
CVE-2026-86889
BR2026-0000-013607
Security
unclaimed
An attacker in a privileged network position may be able to intercept network traffic
Credited as Taekyoung Kwon from SNU CSE MMLAB (mmlab.snu.ac.kr)
CVE-2026-86881
BR2026-0000-013608
Security
unclaimed
An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages
Credited as Surya Narayan Kushwaha
CVE-2026-86881
BR2026-0000-013609
Security
unclaimed
An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages
Credited as Roman Zabicki
CVE-2026-86881
BR2026-0000-013610
Security
unclaimed
An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages
Credited as John Lussier
CVE-2026-86881
BR2026-0000-013611
Security
unclaimed
An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages
Credited as Filip Olszak
CVE-2026-43719
BR2026-0000-013612
SMB
unclaimed
Mounting a maliciously crafted SMB network share may lead to system termination
Credited as Jakob Pammer
CVE-2026-43719
BR2026-0000-013613
SMB
unclaimed
Mounting a maliciously crafted SMB network share may lead to system termination
Credited as Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-84543
BR2026-0000-013614
SMB
unclaimed
Connecting to a malicious SMB server may cause unexpected system termination or corrupt kernel memory
Credited as Peter Malone
CVE-2026-43690
BR2026-0000-013615
SMB
unclaimed
A local user may be able to read kernel memory
Credited as Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-65376
BR2026-0000-013616
SMB
unclaimed
An app may be able to cause unexpected system termination
Credited as 재영 정
CVE-2026-65376
BR2026-0000-013617
SMB
unclaimed
An app may be able to cause unexpected system termination
Credited as Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-84536
BR2026-0000-013618
SMB
unclaimed
Connecting to a malicious SMB server may lead to unexpected system termination
Credited as 재영 정