Early access: this site has moved to bugrater.com.

Security releases

Apple

visionOS 26.6

128070 Jul 27, 2026 Source: Vendor

Imported by the Apple release catcher from https://support.apple.com/en-us/128070. 99 CVE entries, 9 additional recognitions. Available for: Apple Vision Pro (all models). Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://support.apple.com/en-us/128070
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

250 lines
Showing 201–207 of 207 matching · page 5 of 5 · clear filters
CVE-2026-43720 BR2026-0000-006167 WebKit Canvas unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Josef Korbel
CVE-2026-64718 BR2026-0000-006168 WebKit Canvas unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as OGINOME Tomohito
CVE-2026-43721 BR2026-0000-006169 WebKit Storage unclaimed
A malicious website may be able to silently hijack clipboard data
Credited as Idan Masas
CVE-2026-43718 BR2026-0000-006170 WebRTC unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Nan Wang (@eternalsakura13)
CVE-2026-64719 BR2026-0000-006171 WebRTC unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Shaheen Fazim
CVE-2026-64726 BR2026-0000-006172 Wi-Fi unclaimed
An attacker in physical proximity may be able to corrupt process memory
Credited as Mathis Mansière
CVE-2026-64726 BR2026-0000-006173 Wi-Fi unclaimed
An attacker in physical proximity may be able to corrupt process memory
Credited as Peter Malone