Apple
visionOS 27
149038 Sep 14, 2026 Source: Vendor
Imported by the Apple release catcher from https://support.apple.com/en-us/149038. 124 CVE entries, 41 additional recognitions. Available for: Apple Vision Pro (all models). Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://support.apple.com/en-us/149038
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
309 lines
Showing 1–50 of 308 matching · page 1 of 7 · clear filters
CVE-2026-86882
BR2026-0000-014932
Accelerate Framework
unclaimed
Processing a maliciously crafted image may lead to unexpected process termination
Credited as Peter Malone
CVE-2026-84523
BR2026-0000-014933
APFS
unclaimed
An app may be able to cause unexpected system termination or write kernel memory
Credited as Cem Onat Karagun
CVE-2026-86888
BR2026-0000-014934
App Store
unclaimed
A local app may be able to read a persistent account identifier
Credited as Zhongcheng Li (CK01)
CVE-2026-20683
BR2026-0000-014935
Apple Account
unclaimed
An app may be able to use the Sign In With Apple authentication flow to access the user's Apple Account
Credited as Dem0ns (@天府简易信工作室)
CVE-2026-20683
BR2026-0000-014936
Apple Account
unclaimed
An app may be able to use the Sign In With Apple authentication flow to access the user's Apple Account
Credited as Abdelhak Kherroubi
CVE-2026-20683
BR2026-0000-014937
Apple Account
unclaimed
An app may be able to use the Sign In With Apple authentication flow to access the user's Apple Account
Credited as Jasminder Pal Singh
CVE-2026-20683
BR2026-0000-014938
Apple Account
unclaimed
An app may be able to use the Sign In With Apple authentication flow to access the user's Apple Account
Credited as Lehan Dilusha Jayasingha (Sri Lanka)
CVE-2026-65407
BR2026-0000-014939
AppleAVD
unclaimed
An app may be able to cause unexpected system termination
Credited as Franco Belman at Blackwing Intelligence
CVE-2026-65339
BR2026-0000-014940
Audio
unclaimed
An app may be able to leak sensitive user information
Credited as Mustafa Calap (@ordinal0, dbg.re)
CVE-2026-65339
BR2026-0000-014941
Audio
unclaimed
An app may be able to leak sensitive user information
Credited as Meta Red Team X - Nik Tsytsarkin
CVE-2026-86905
BR2026-0000-014942
Authentication Services
unclaimed
An app may be able to delete credentials stored in Keychain
Credited as Ilya Andr (andrd3v)
CVE-2026-84583
BR2026-0000-014943
AuthKit
unclaimed
A local app may be able to read a persistent account identifier
Credited as Zhongcheng Li from IES Red Team
CVE-2026-65410
BR2026-0000-014944
AVEVideoEncoder
unclaimed
An app may be able to cause unexpected system termination
Credited as Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-84616
BR2026-0000-014945
AVEVideoEncoder
unclaimed
An app may be able to cause unexpected system termination
Credited as Peter Malone
CVE-2026-84607
BR2026-0000-014946
AVEVideoEncoder
unclaimed
A sandboxed app may be able to execute arbitrary code with kernel privileges
Credited as Ruslan Dautov
CVE-2026-65406
BR2026-0000-014947
BackgroundAssets
unclaimed
An app may be able to access sensitive user data
Credited as Ye Zhang (@VAR10CK) of Baidu Security
CVE-2026-86895
BR2026-0000-014948
CloudKit
unclaimed
A local app may be able to read a persistent account identifier
Credited as Stanislav Jelezoglo
CVE-2026-86893
BR2026-0000-014949
CloudKit
unclaimed
An app may be able to read device name
Credited as Heiner Gerdes
CVE-2026-65399
BR2026-0000-014950
copyfile
unclaimed
An archive may be able to bypass Gatekeeper
Credited as Rishabh Jain (rjcyber) of cyberplanet
CVE-2026-65399
BR2026-0000-014951
copyfile
unclaimed
An archive may be able to bypass Gatekeeper
Credited as Pasquale Scola
CVE-2026-64752
BR2026-0000-014952
CoreMedia
unclaimed
Processing a maliciously crafted image may lead to arbitrary code execution
Credited as Nik Tsytsarkin
CVE-2026-86876
BR2026-0000-014953
CoreMedia
unclaimed
A sandboxed process may be able to circumvent sandbox restrictions
Credited as Chris Bailey - Short Circuit
CVE-2026-65344
BR2026-0000-014954
CoreMedia
unclaimed
Processing a maliciously crafted video file may lead to unexpected app termination
Credited as Siyeong kim
CVE-2026-84624
BR2026-0000-014955
CoreML
unclaimed
A sandboxed app may be able to access restricted files
Credited as AL Najafi
CVE-2026-84624
BR2026-0000-014956
CoreML
unclaimed
A sandboxed app may be able to access restricted files
Credited as tamdao
CVE-2026-65412
BR2026-0000-014957
CoreText
unclaimed
Processing web content may lead to a denial-of-service
Credited as Pavan Nallamothu
CVE-2026-84596
BR2026-0000-014958
CoreText
unclaimed
Processing a maliciously crafted font may result in the disclosure of process memory
Credited as ret2happy
CVE-2026-84596
BR2026-0000-014959
CoreText
unclaimed
Processing a maliciously crafted font may result in the disclosure of process memory
Credited as Meta Product Security
CVE-2026-84575
BR2026-0000-014960
CoreUI
unclaimed
Processing a maliciously crafted file may lead to unexpected app termination
Credited as Mustafa Calap (@ordinal0, dbg.re)
CVE-2026-84571
BR2026-0000-014961
CoreUI
unclaimed
Processing a maliciously crafted image may lead to unexpected app termination
Credited as stratan (@5tratan)
CVE-2026-84571
BR2026-0000-014962
CoreUI
unclaimed
Processing a maliciously crafted image may lead to unexpected app termination
Credited as Peter Malone
CVE-2026-84511
BR2026-0000-014963
CoreUI
unclaimed
Processing a maliciously crafted asset catalog may lead to unexpected process termination
Credited as Rahul Raj
CVE-2026-84511
BR2026-0000-014964
CoreUI
unclaimed
Processing a maliciously crafted asset catalog may lead to unexpected process termination
Credited as stratan (@5tratan)
CVE-2026-84612
BR2026-0000-014965
DeviceCheck
unclaimed
An app may be able to read persistent device identifiers
Credited as N.M.Praveen Nawarathne (@zblockrat)
CVE-2026-84612
BR2026-0000-014966
DeviceCheck
unclaimed
An app may be able to read persistent device identifiers
Credited as James Gill (@jjtech@infosec.exchange)
CVE-2026-43785
BR2026-0000-014967
File Bookmark
unclaimed
An app may be able to modify a file it only had permission to read
Credited as Junyeong Lee (jylab.github.io)
CVE-2026-43785
BR2026-0000-014968
File Bookmark
unclaimed
An app may be able to modify a file it only had permission to read
Credited as Merrick Hare
CVE-2026-43785
BR2026-0000-014969
File Bookmark
unclaimed
An app may be able to modify a file it only had permission to read
Credited as Aditya Kumar
CVE-2026-43785
BR2026-0000-014970
File Bookmark
unclaimed
An app may be able to modify a file it only had permission to read
Credited as John Nzyuko Uvyu
CVE-2026-43785
BR2026-0000-014971
File Bookmark
unclaimed
An app may be able to modify a file it only had permission to read
Credited as Narendra Singh (@_3P1C)
CVE-2026-84534
BR2026-0000-014972
file_cmds
unclaimed
Extracting a maliciously crafted archive may allow an attacker to write arbitrary files
Credited as Geoffrey Lovelace
CVE-2026-84597
BR2026-0000-014973
FontParser
unclaimed
Processing a maliciously crafted font may result in the disclosure of process memory
Credited as Nik Tsytsarkin
CVE-2026-65409
BR2026-0000-014974
Foundation
unclaimed
An app may be able to cause a denial of service
Credited as Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-84492
BR2026-0000-014975
Graphics
unclaimed
An app may be able to cause unexpected system termination
Credited as Tommy DeVoss from Braze Security Team (@thedawgyg)
CVE-2026-84492
BR2026-0000-014976
Graphics
unclaimed
An app may be able to cause unexpected system termination
Credited as Jiyong Yang
CVE-2026-84606
BR2026-0000-014977
iCloud
unclaimed
An app may be able to identify a user across reinstalls
Credited as Ilya Andr (andrd3v)
CVE-2026-84564
BR2026-0000-014978
ImageIO
unclaimed
Processing a maliciously crafted image may result in disclosure of process memory
Credited as Justin O'Leary
CVE-2026-65347
BR2026-0000-014979
ImageIO
unclaimed
Processing an image may lead to a denial-of-service
Credited as Geonha Lee (@leegn4a)
CVE-2026-65346
BR2026-0000-014980
ImageIO
unclaimed
Processing an image may lead to arbitrary code execution
Credited as Meta Red Team X - Nik Tsytsarkin
CVE-2026-65395
BR2026-0000-014981
ImageIO
unclaimed
Processing a maliciously crafted image may result in memory corruption
Credited as Mateusz Jurczyk of Google Project Zero