Early access: this site has moved to bugrater.com.

Security releases

Apple

macOS Tahoe 26.7

149042 Sep 14, 2026 Source: Vendor

Imported by the Apple release catcher from https://support.apple.com/en-us/149042. 154 CVE entries, 12 additional recognitions. Available for: macOS Tahoe. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://support.apple.com/en-us/149042
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

315 lines
Showing 201–250 of 299 matching · page 5 of 6 · clear filters
CVE-2026-43741 BR2026-0000-013569 Messages unclaimed
An app may be able to access protected user data
Credited as Dawuge of Shuffle Team
CVE-2026-86924 BR2026-0000-013570 MobileAccessoryUpdater unclaimed
Connecting a malicious accessory may cause unexpected system termination
Credited as Matthew Zamat
CVE-2026-84497 BR2026-0000-013571 Model I/O unclaimed
Opening a maliciously crafted file may lead to unexpected process termination
Credited as Yiğit Can YILMAZ (@yilmazcanyigit)
CVE-2026-84626 BR2026-0000-013572 NetworkExtension unclaimed
An app may be able to identify what other apps a user has installed
Credited as Sindre Sorhus
CVE-2026-84626 BR2026-0000-013573 NetworkExtension unclaimed
An app may be able to identify what other apps a user has installed
Credited as Hoffcona of IES Red Team
CVE-2026-43695 BR2026-0000-013574 NetworkExtension unclaimed
An app may be able to access sensitive user data
Credited as Claudio Bozzato
CVE-2026-43695 BR2026-0000-013575 NetworkExtension unclaimed
An app may be able to access sensitive user data
Credited as Francesco Benvenuto of Cisco Talos
CVE-2026-64712 BR2026-0000-013576 odproxyd unclaimed
An app may be able to gain root privileges
Credited as Andreas Jaegersberger
CVE-2026-64712 BR2026-0000-013577 odproxyd unclaimed
An app may be able to gain root privileges
Credited as Ro Achterberg of Nosebeard Labs
CVE-2026-84578 BR2026-0000-013578 quarantine unclaimed
An app may be able to break out of its sandbox
Credited as Kenneth Chew
CVE-2026-84576 BR2026-0000-013579 QuartzCore unclaimed
An app may be able to access sensitive user data
Credited as Dora Orak
CVE-2026-84576 BR2026-0000-013580 QuartzCore unclaimed
An app may be able to access sensitive user data
Credited as @Ethan Arbuckle
CVE-2026-84576 BR2026-0000-013581 QuartzCore unclaimed
An app may be able to access sensitive user data
Credited as and @leptos_null
CVE-2026-84548 BR2026-0000-013582 Quick Look unclaimed
Processing a maliciously crafted document may lead to an out-of-bounds read
Credited as Peter Malone
CVE-2026-84532 BR2026-0000-013583 RealityKit unclaimed
Opening a maliciously crafted file may cause unexpected process termination or disclose process memory
Credited as stratan (@5tratan)
CVE-2026-84532 BR2026-0000-013584 RealityKit unclaimed
Opening a maliciously crafted file may cause unexpected process termination or disclose process memory
Credited as Hongsik Kim (mnur)
CVE-2026-28966 BR2026-0000-013585 RealityKit unclaimed
Processing a maliciously crafted file may lead to unexpected app termination
Credited as stratan (@5tratan)
CVE-2026-65403 BR2026-0000-013586 Reminders unclaimed
An app may be able to access sensitive user data
Credited as Rahul Raj
CVE-2026-84487 BR2026-0000-013587 SceneKit unclaimed
Processing a maliciously crafted file may result in disclosure of process memory
Credited as stratan (@5tratan)
CVE-2026-84487 BR2026-0000-013588 SceneKit unclaimed
Processing a maliciously crafted file may result in disclosure of process memory
Credited as Peter Malone
CVE-2026-84487 BR2026-0000-013589 SceneKit unclaimed
Processing a maliciously crafted file may result in disclosure of process memory
Credited as Dhiyanesh Selvaraj (@redroot97)
CVE-2026-65413 BR2026-0000-013590 SceneKit unclaimed
An app may be able to cause a denial of service
Credited as Peter Malone
CVE-2026-84546 BR2026-0000-013591 SceneKit unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as Narendra Singh (@_3P1C)
CVE-2026-84546 BR2026-0000-013592 SceneKit unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as stratan (@5tratan)
CVE-2026-84546 BR2026-0000-013593 SceneKit unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as Peter Malone
CVE-2026-84611 BR2026-0000-013594 SceneKit unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as Nathaniel Oh (@calysteon)
CVE-2026-84632 BR2026-0000-013595 SceneKit unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as Peter Malone
CVE-2026-84620 BR2026-0000-013596 SceneKit unclaimed
Processing a maliciously crafted 3D model may lead to memory corruption
Credited as Peter Malone
CVE-2026-43697 BR2026-0000-013597 SceneKit unclaimed
Processing a maliciously crafted 3D file may lead to an out-of-bounds read
Credited as Peter Malone
CVE-2026-84526 BR2026-0000-013598 SceneKit unclaimed
Processing a maliciously crafted 3D scene may lead to unexpected process termination
Credited as stratan (@5tratan)
CVE-2026-43760 BR2026-0000-013599 Screen Sharing Server unclaimed
An app may be able to access user-sensitive data
Credited as Alfredo Pesoli (@__rev) of Bynar.io
CVE-2026-43760 BR2026-0000-013600 Screen Sharing Server unclaimed
An app may be able to access user-sensitive data
Credited as wdszzml
CVE-2026-43760 BR2026-0000-013601 Screen Sharing Server unclaimed
An app may be able to access user-sensitive data
Credited as Atuin Automated Vulnerability Discovery Engine
CVE-2026-65400 BR2026-0000-013602 Screen Sharing Server unclaimed
An attacker on the network may be able to authenticate to Screen Sharing without valid credentials
Credited as Alfredo Pesoli (@__rev) via Bynario Atlas (bynar.io)
CVE-2026-86889 BR2026-0000-013603 Security unclaimed
An attacker in a privileged network position may be able to intercept network traffic
Credited as Jaeho Nam
CVE-2026-86889 BR2026-0000-013604 Security unclaimed
An attacker in a privileged network position may be able to intercept network traffic
Credited as Jungbum Lee
CVE-2026-86889 BR2026-0000-013605 Security unclaimed
An attacker in a privileged network position may be able to intercept network traffic
Credited as Sangwi Kang
CVE-2026-86889 BR2026-0000-013606 Security unclaimed
An attacker in a privileged network position may be able to intercept network traffic
Credited as Hyeonguk Ko
CVE-2026-86889 BR2026-0000-013607 Security unclaimed
An attacker in a privileged network position may be able to intercept network traffic
Credited as Taekyoung Kwon from SNU CSE MMLAB (mmlab.snu.ac.kr)
CVE-2026-86881 BR2026-0000-013608 Security unclaimed
An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages
Credited as Surya Narayan Kushwaha
CVE-2026-86881 BR2026-0000-013609 Security unclaimed
An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages
Credited as Roman Zabicki
CVE-2026-86881 BR2026-0000-013610 Security unclaimed
An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages
Credited as John Lussier
CVE-2026-86881 BR2026-0000-013611 Security unclaimed
An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages
Credited as Filip Olszak
CVE-2026-43719 BR2026-0000-013612 SMB unclaimed
Mounting a maliciously crafted SMB network share may lead to system termination
Credited as Jakob Pammer
CVE-2026-43719 BR2026-0000-013613 SMB unclaimed
Mounting a maliciously crafted SMB network share may lead to system termination
Credited as Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-84543 BR2026-0000-013614 SMB unclaimed
Connecting to a malicious SMB server may cause unexpected system termination or corrupt kernel memory
Credited as Peter Malone
CVE-2026-43690 BR2026-0000-013615 SMB unclaimed
A local user may be able to read kernel memory
Credited as Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-65376 BR2026-0000-013616 SMB unclaimed
An app may be able to cause unexpected system termination
Credited as 재영 정
CVE-2026-65376 BR2026-0000-013617 SMB unclaimed
An app may be able to cause unexpected system termination
Credited as Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-84536 BR2026-0000-013618 SMB unclaimed
Connecting to a malicious SMB server may lead to unexpected system termination
Credited as 재영 정