Early access: this site has moved to bugrater.com.

Security releases

Apple

watchOS 27

149037 Sep 14, 2026 Source: Vendor

Imported by the Apple release catcher from https://support.apple.com/en-us/149037. 93 CVE entries, 31 additional recognitions. Available for: Apple Watch Series 9 and later. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://support.apple.com/en-us/149037
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

244 lines
Showing 151–164 of 164 matching · page 4 of 4 · clear filters
CVE-2026-84527 BR2026-0000-014838 TCC unclaimed
An app may be able to access sensitive user data
Credited as Zeyang Li&Yuxiang Wang of Chongqing Telecom
CVE-2026-86904 BR2026-0000-014839 Watch App unclaimed
An app may be able to track users across apps and websites without permission
Credited as Stanislav Jelezoglo
CVE-2026-84635 BR2026-0000-014840 WebKit unclaimed
Processing maliciously crafted web content may lead to an unexpected process termination
Credited as Souta Sugiyama
CVE-2026-65341 BR2026-0000-014841 WebKit unclaimed
Processing maliciously crafted web content may lead to memory corruption
Credited as Henock Habte
CVE-2026-64753 BR2026-0000-014842 WebKit unclaimed
Processing maliciously crafted web content may disclose sensitive user information
Credited as Viggo Lekdorf
CVE-2026-64715 BR2026-0000-014843 WebKit unclaimed
Processing maliciously crafted web content may lead to an unexpected process crash
Credited as Hossein Lotfi (@hosselot) of TrendAI Zero Day Initiative
CVE-2026-64787 BR2026-0000-014844 WebKit unclaimed
Processing maliciously crafted web content may lead to an unexpected process termination
Credited as 杉山 壮太
CVE-2026-64787 BR2026-0000-014845 WebKit unclaimed
Processing maliciously crafted web content may lead to an unexpected process termination
Credited as Shubham Chaskar
CVE-2026-43794 BR2026-0000-014846 WebKit unclaimed
Processing maliciously crafted web content may lead to memory corruption
Credited as Dung Do (@_piers2) of Calif.io
CVE-2026-64778 BR2026-0000-014847 WebKit History unclaimed
Visiting a maliciously crafted website may leak sensitive data
Credited as Mohit Negi
CVE-2026-65391 BR2026-0000-014848 WebRTC unclaimed
Processing maliciously crafted web content may lead to memory corruption
Credited as Myungyong Lee
CVE-2026-65390 BR2026-0000-014849 WebRTC unclaimed
Processing maliciously crafted web content may lead to memory corruption
Credited as Kwak Kiyong (@Pwnkai23)
CVE-2026-65390 BR2026-0000-014850 WebRTC unclaimed
Processing maliciously crafted web content may lead to memory corruption
Credited as Song Nuri
CVE-2026-84636 BR2026-0000-014851 Wi-Fi Connectivity unclaimed
An app may be able to access sensitive user data
Credited as Jian Lee (@speedyfriend433)