Early access: this site has moved to bugrater.com.

Security releases

Apple

watchOS 27

149037 Sep 14, 2026 Source: Vendor

Imported by the Apple release catcher from https://support.apple.com/en-us/149037. 93 CVE entries, 31 additional recognitions. Available for: Apple Watch Series 9 and later. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://support.apple.com/en-us/149037
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

244 lines
Showing 1–50 of 243 matching · page 1 of 5 · clear filters
CVE-2026-86882 BR2026-0000-014688 Accelerate Framework unclaimed
Processing a maliciously crafted image may lead to unexpected process termination
Credited as Peter Malone
CVE-2026-43664 BR2026-0000-014689 Accessibility unclaimed
An app may be able to access sensitive user data
Credited as Stuart Wallace
CVE-2026-43664 BR2026-0000-014690 Accessibility unclaimed
An app may be able to access sensitive user data
Credited as Ilya Andr (andrd3v)
CVE-2026-43664 BR2026-0000-014691 Accessibility unclaimed
An app may be able to access sensitive user data
Credited as Rosyna Keller of Totally Not Malicious Software
CVE-2026-43664 BR2026-0000-014692 Accessibility unclaimed
An app may be able to access sensitive user data
Credited as CJ Vana
CVE-2026-43664 BR2026-0000-014693 Accessibility unclaimed
An app may be able to access sensitive user data
Credited as David Strnadel
CVE-2026-43664 BR2026-0000-014694 Accessibility unclaimed
An app may be able to access sensitive user data
Credited as Daniel Febrero
CVE-2026-43664 BR2026-0000-014695 Accessibility unclaimed
An app may be able to access sensitive user data
Credited as Asaf Cohen
CVE-2026-43664 BR2026-0000-014696 Accessibility unclaimed
An app may be able to access sensitive user data
Credited as Gongyu Ma (@Mezone0)
CVE-2026-43664 BR2026-0000-014697 Accessibility unclaimed
An app may be able to access sensitive user data
Credited as Jian Lee (@speedyfriend433)
CVE-2026-84523 BR2026-0000-014698 APFS unclaimed
An app may be able to cause unexpected system termination or write kernel memory
Credited as Cem Onat Karagun
CVE-2026-86888 BR2026-0000-014699 App Store unclaimed
A local app may be able to read a persistent account identifier
Credited as Zhongcheng Li (CK01)
CVE-2026-84586 BR2026-0000-014700 Apple Account unclaimed
A malicious application may be able to leak sensitive user information
Credited as Prashan Samarathunge
CVE-2026-84586 BR2026-0000-014701 Apple Account unclaimed
A malicious application may be able to leak sensitive user information
Credited as Zhongcheng Li (CK01)
CVE-2026-65407 BR2026-0000-014702 AppleAVD unclaimed
An app may be able to cause unexpected system termination
Credited as Franco Belman at Blackwing Intelligence
CVE-2026-65339 BR2026-0000-014703 Audio unclaimed
An app may be able to leak sensitive user information
Credited as Mustafa Calap (@ordinal0, dbg.re)
CVE-2026-65339 BR2026-0000-014704 Audio unclaimed
An app may be able to leak sensitive user information
Credited as Meta Red Team X - Nik Tsytsarkin
CVE-2026-84583 BR2026-0000-014705 AuthKit unclaimed
A local app may be able to read a persistent account identifier
Credited as Zhongcheng Li from IES Red Team
CVE-2026-65410 BR2026-0000-014706 AVEVideoEncoder unclaimed
An app may be able to cause unexpected system termination
Credited as Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-84616 BR2026-0000-014707 AVEVideoEncoder unclaimed
An app may be able to cause unexpected system termination
Credited as Peter Malone
CVE-2026-84607 BR2026-0000-014708 AVEVideoEncoder unclaimed
A sandboxed app may be able to execute arbitrary code with kernel privileges
Credited as Ruslan Dautov
CVE-2026-86895 BR2026-0000-014709 CloudKit unclaimed
A local app may be able to read a persistent account identifier
Credited as Stanislav Jelezoglo
CVE-2026-86893 BR2026-0000-014710 CloudKit unclaimed
An app may be able to read device name
Credited as Heiner Gerdes
CVE-2026-65399 BR2026-0000-014711 copyfile unclaimed
An archive may be able to bypass Gatekeeper
Credited as Rishabh Jain (rjcyber) of cyberplanet
CVE-2026-65399 BR2026-0000-014712 copyfile unclaimed
An archive may be able to bypass Gatekeeper
Credited as Pasquale Scola
CVE-2026-86891 BR2026-0000-014713 Core Bluetooth unclaimed
An app may be able to access Bluetooth device information
Credited as Dawuge of Shuffle Team
CVE-2026-86876 BR2026-0000-014714 CoreMedia unclaimed
A sandboxed process may be able to circumvent sandbox restrictions
Credited as Chris Bailey - Short Circuit
CVE-2026-43737 BR2026-0000-014715 CoreMotion unclaimed
An app may be able to access motion data from headphones without user consent
Credited as Stuart Wallace
CVE-2026-65412 BR2026-0000-014716 CoreText unclaimed
Processing web content may lead to a denial-of-service
Credited as Pavan Nallamothu
CVE-2026-84596 BR2026-0000-014717 CoreText unclaimed
Processing a maliciously crafted font may result in the disclosure of process memory
Credited as ret2happy
CVE-2026-84596 BR2026-0000-014718 CoreText unclaimed
Processing a maliciously crafted font may result in the disclosure of process memory
Credited as Meta Product Security
CVE-2026-84575 BR2026-0000-014719 CoreUI unclaimed
Processing a maliciously crafted file may lead to unexpected app termination
Credited as Mustafa Calap (@ordinal0, dbg.re)
CVE-2026-84571 BR2026-0000-014720 CoreUI unclaimed
Processing a maliciously crafted image may lead to unexpected app termination
Credited as stratan (@5tratan)
CVE-2026-84571 BR2026-0000-014721 CoreUI unclaimed
Processing a maliciously crafted image may lead to unexpected app termination
Credited as Peter Malone
CVE-2026-84511 BR2026-0000-014722 CoreUI unclaimed
Processing a maliciously crafted asset catalog may lead to unexpected process termination
Credited as Rahul Raj
CVE-2026-84511 BR2026-0000-014723 CoreUI unclaimed
Processing a maliciously crafted asset catalog may lead to unexpected process termination
Credited as stratan (@5tratan)
CVE-2026-84612 BR2026-0000-014724 DeviceCheck unclaimed
An app may be able to read persistent device identifiers
Credited as N.M.Praveen Nawarathne (@zblockrat)
CVE-2026-84612 BR2026-0000-014725 DeviceCheck unclaimed
An app may be able to read persistent device identifiers
Credited as James Gill (@jjtech@infosec.exchange)
CVE-2026-84597 BR2026-0000-014726 FontParser unclaimed
Processing a maliciously crafted font may result in the disclosure of process memory
Credited as Nik Tsytsarkin
CVE-2026-65409 BR2026-0000-014727 Foundation unclaimed
An app may be able to cause a denial of service
Credited as Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-84492 BR2026-0000-014728 Graphics unclaimed
An app may be able to cause unexpected system termination
Credited as Tommy DeVoss from Braze Security Team (@thedawgyg)
CVE-2026-84492 BR2026-0000-014729 Graphics unclaimed
An app may be able to cause unexpected system termination
Credited as Jiyong Yang
CVE-2026-84533 BR2026-0000-014730 Heimdal unclaimed
An attacker in a privileged network position may be able to modify network traffic
Credited as Vishal Patidar
CVE-2026-84533 BR2026-0000-014731 Heimdal unclaimed
An attacker in a privileged network position may be able to modify network traffic
Credited as Roman Zabicki
CVE-2026-84564 BR2026-0000-014732 ImageIO unclaimed
Processing a maliciously crafted image may result in disclosure of process memory
Credited as Justin O'Leary
CVE-2026-65347 BR2026-0000-014733 ImageIO unclaimed
Processing an image may lead to a denial-of-service
Credited as Geonha Lee (@leegn4a)
CVE-2026-65346 BR2026-0000-014734 ImageIO unclaimed
Processing an image may lead to arbitrary code execution
Credited as Meta Red Team X - Nik Tsytsarkin
CVE-2026-64788 BR2026-0000-014735 IOGPUFamily unclaimed
Processing maliciously crafted web content may lead to memory corruption
Credited as f00l (@PPPF00L)
CVE-2026-64788 BR2026-0000-014736 IOGPUFamily unclaimed
Processing maliciously crafted web content may lead to memory corruption
Credited as 3ndy1(@_3ndy1)
CVE-2026-64788 BR2026-0000-014737 IOGPUFamily unclaimed
Processing maliciously crafted web content may lead to memory corruption
Credited as Minghao Lin@Y1nkoc