Apple
watchOS 27
149037 Sep 14, 2026 Source: Vendor
Imported by the Apple release catcher from https://support.apple.com/en-us/149037. 93 CVE entries, 31 additional recognitions. Available for: Apple Watch Series 9 and later. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://support.apple.com/en-us/149037
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
244 lines
Showing 1–50 of 243 matching · page 1 of 5 · clear filters
CVE-2026-86882
BR2026-0000-014688
Accelerate Framework
unclaimed
Processing a maliciously crafted image may lead to unexpected process termination
Credited as Peter Malone
CVE-2026-43664
BR2026-0000-014689
Accessibility
unclaimed
An app may be able to access sensitive user data
Credited as Stuart Wallace
CVE-2026-43664
BR2026-0000-014690
Accessibility
unclaimed
An app may be able to access sensitive user data
Credited as Ilya Andr (andrd3v)
CVE-2026-43664
BR2026-0000-014691
Accessibility
unclaimed
An app may be able to access sensitive user data
Credited as Rosyna Keller of Totally Not Malicious Software
CVE-2026-43664
BR2026-0000-014692
Accessibility
unclaimed
An app may be able to access sensitive user data
Credited as CJ Vana
CVE-2026-43664
BR2026-0000-014693
Accessibility
unclaimed
An app may be able to access sensitive user data
Credited as David Strnadel
CVE-2026-43664
BR2026-0000-014694
Accessibility
unclaimed
An app may be able to access sensitive user data
Credited as Daniel Febrero
CVE-2026-43664
BR2026-0000-014695
Accessibility
unclaimed
An app may be able to access sensitive user data
Credited as Asaf Cohen
CVE-2026-43664
BR2026-0000-014696
Accessibility
unclaimed
An app may be able to access sensitive user data
Credited as Gongyu Ma (@Mezone0)
CVE-2026-43664
BR2026-0000-014697
Accessibility
unclaimed
An app may be able to access sensitive user data
Credited as Jian Lee (@speedyfriend433)
CVE-2026-84523
BR2026-0000-014698
APFS
unclaimed
An app may be able to cause unexpected system termination or write kernel memory
Credited as Cem Onat Karagun
CVE-2026-86888
BR2026-0000-014699
App Store
unclaimed
A local app may be able to read a persistent account identifier
Credited as Zhongcheng Li (CK01)
CVE-2026-84586
BR2026-0000-014700
Apple Account
unclaimed
A malicious application may be able to leak sensitive user information
Credited as Prashan Samarathunge
CVE-2026-84586
BR2026-0000-014701
Apple Account
unclaimed
A malicious application may be able to leak sensitive user information
Credited as Zhongcheng Li (CK01)
CVE-2026-65407
BR2026-0000-014702
AppleAVD
unclaimed
An app may be able to cause unexpected system termination
Credited as Franco Belman at Blackwing Intelligence
CVE-2026-65339
BR2026-0000-014703
Audio
unclaimed
An app may be able to leak sensitive user information
Credited as Mustafa Calap (@ordinal0, dbg.re)
CVE-2026-65339
BR2026-0000-014704
Audio
unclaimed
An app may be able to leak sensitive user information
Credited as Meta Red Team X - Nik Tsytsarkin
CVE-2026-84583
BR2026-0000-014705
AuthKit
unclaimed
A local app may be able to read a persistent account identifier
Credited as Zhongcheng Li from IES Red Team
CVE-2026-65410
BR2026-0000-014706
AVEVideoEncoder
unclaimed
An app may be able to cause unexpected system termination
Credited as Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-84616
BR2026-0000-014707
AVEVideoEncoder
unclaimed
An app may be able to cause unexpected system termination
Credited as Peter Malone
CVE-2026-84607
BR2026-0000-014708
AVEVideoEncoder
unclaimed
A sandboxed app may be able to execute arbitrary code with kernel privileges
Credited as Ruslan Dautov
CVE-2026-86895
BR2026-0000-014709
CloudKit
unclaimed
A local app may be able to read a persistent account identifier
Credited as Stanislav Jelezoglo
CVE-2026-86893
BR2026-0000-014710
CloudKit
unclaimed
An app may be able to read device name
Credited as Heiner Gerdes
CVE-2026-65399
BR2026-0000-014711
copyfile
unclaimed
An archive may be able to bypass Gatekeeper
Credited as Rishabh Jain (rjcyber) of cyberplanet
CVE-2026-65399
BR2026-0000-014712
copyfile
unclaimed
An archive may be able to bypass Gatekeeper
Credited as Pasquale Scola
CVE-2026-86891
BR2026-0000-014713
Core Bluetooth
unclaimed
An app may be able to access Bluetooth device information
Credited as Dawuge of Shuffle Team
CVE-2026-86876
BR2026-0000-014714
CoreMedia
unclaimed
A sandboxed process may be able to circumvent sandbox restrictions
Credited as Chris Bailey - Short Circuit
CVE-2026-43737
BR2026-0000-014715
CoreMotion
unclaimed
An app may be able to access motion data from headphones without user consent
Credited as Stuart Wallace
CVE-2026-65412
BR2026-0000-014716
CoreText
unclaimed
Processing web content may lead to a denial-of-service
Credited as Pavan Nallamothu
CVE-2026-84596
BR2026-0000-014717
CoreText
unclaimed
Processing a maliciously crafted font may result in the disclosure of process memory
Credited as ret2happy
CVE-2026-84596
BR2026-0000-014718
CoreText
unclaimed
Processing a maliciously crafted font may result in the disclosure of process memory
Credited as Meta Product Security
CVE-2026-84575
BR2026-0000-014719
CoreUI
unclaimed
Processing a maliciously crafted file may lead to unexpected app termination
Credited as Mustafa Calap (@ordinal0, dbg.re)
CVE-2026-84571
BR2026-0000-014720
CoreUI
unclaimed
Processing a maliciously crafted image may lead to unexpected app termination
Credited as stratan (@5tratan)
CVE-2026-84571
BR2026-0000-014721
CoreUI
unclaimed
Processing a maliciously crafted image may lead to unexpected app termination
Credited as Peter Malone
CVE-2026-84511
BR2026-0000-014722
CoreUI
unclaimed
Processing a maliciously crafted asset catalog may lead to unexpected process termination
Credited as Rahul Raj
CVE-2026-84511
BR2026-0000-014723
CoreUI
unclaimed
Processing a maliciously crafted asset catalog may lead to unexpected process termination
Credited as stratan (@5tratan)
CVE-2026-84612
BR2026-0000-014724
DeviceCheck
unclaimed
An app may be able to read persistent device identifiers
Credited as N.M.Praveen Nawarathne (@zblockrat)
CVE-2026-84612
BR2026-0000-014725
DeviceCheck
unclaimed
An app may be able to read persistent device identifiers
Credited as James Gill (@jjtech@infosec.exchange)
CVE-2026-84597
BR2026-0000-014726
FontParser
unclaimed
Processing a maliciously crafted font may result in the disclosure of process memory
Credited as Nik Tsytsarkin
CVE-2026-65409
BR2026-0000-014727
Foundation
unclaimed
An app may be able to cause a denial of service
Credited as Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-84492
BR2026-0000-014728
Graphics
unclaimed
An app may be able to cause unexpected system termination
Credited as Tommy DeVoss from Braze Security Team (@thedawgyg)
CVE-2026-84492
BR2026-0000-014729
Graphics
unclaimed
An app may be able to cause unexpected system termination
Credited as Jiyong Yang
CVE-2026-84533
BR2026-0000-014730
Heimdal
unclaimed
An attacker in a privileged network position may be able to modify network traffic
Credited as Vishal Patidar
CVE-2026-84533
BR2026-0000-014731
Heimdal
unclaimed
An attacker in a privileged network position may be able to modify network traffic
Credited as Roman Zabicki
CVE-2026-84564
BR2026-0000-014732
ImageIO
unclaimed
Processing a maliciously crafted image may result in disclosure of process memory
Credited as Justin O'Leary
CVE-2026-65347
BR2026-0000-014733
ImageIO
unclaimed
Processing an image may lead to a denial-of-service
Credited as Geonha Lee (@leegn4a)
CVE-2026-65346
BR2026-0000-014734
ImageIO
unclaimed
Processing an image may lead to arbitrary code execution
Credited as Meta Red Team X - Nik Tsytsarkin
CVE-2026-64788
BR2026-0000-014735
IOGPUFamily
unclaimed
Processing maliciously crafted web content may lead to memory corruption
Credited as f00l (@PPPF00L)
CVE-2026-64788
BR2026-0000-014736
IOGPUFamily
unclaimed
Processing maliciously crafted web content may lead to memory corruption
Credited as 3ndy1(@_3ndy1)
CVE-2026-64788
BR2026-0000-014737
IOGPUFamily
unclaimed
Processing maliciously crafted web content may lead to memory corruption
Credited as Minghao Lin@Y1nkoc