<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Apple iOS (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/ios.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/ios-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Apple iOS (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:32 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-44698 – Home Assistant is open source home automation software that puts local control a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44698</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44698</guid>
    <pubDate>Fri, 29 May 2026 14:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44698</strong></p>
  <p>Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home Assistant Companion apps for Android and iOS expose a JavaScript bridge to the in-app WebView window.externalApp on Android and webkit.messageHandlers.getExternalAuth (alongside revokeExternalAuth and externalBus) on iOS. Two flaws expose th…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44698">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9963 – Uninitialized Use in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9963</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9963</guid>
    <pubDate>Thu, 28 May 2026 23:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9963</strong></p>
  <p>Uninitialized Use in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-457</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9963">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9956 – Use after free in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9956</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9956</guid>
    <pubDate>Thu, 28 May 2026 23:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9956</strong></p>
  <p>Use after free in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9956">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47973 – Sticky Notes Widget 3.0.6 contains a denial of service vulnerability that allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47973</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47973</guid>
    <pubDate>Sat, 16 May 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47973</strong></p>
  <p>Sticky Notes Widget 3.0.6 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character strings into note fields. Attackers can generate a payload containing 350000 repeated characters and paste it twice into a new note to trigger an application crash on iOS devices.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47973">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8585 – Inappropriate implementation in Media in Google Chrome on iOS prior to 148.0.777...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8585</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8585</guid>
    <pubDate>Thu, 14 May 2026 20:17:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8585</strong></p>
  <p>Inappropriate implementation in Media in Google Chrome on iOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8585">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46311 – An inconsistent user interface issue was addressed with improved state managemen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46311</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46311</guid>
    <pubDate>Tue, 12 May 2026 18:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46311</strong></p>
  <p>An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2. An app may be able to access sensitive user data.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-451</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46311">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43668 – A use after free issue was addressed with improved memory management. This issue...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43668</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43668</guid>
    <pubDate>Mon, 11 May 2026 21:19:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43668</strong></p>
  <p>A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43668">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43661 – A buffer overflow issue was addressed with improved memory handling. This issue ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43661</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43661</guid>
    <pubDate>Mon, 11 May 2026 21:19:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43661</strong></p>
  <p>A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. Processing a maliciously crafted image may corrupt process memory.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43661">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43660 – A validation issue was addressed with improved logic. This issue is fixed in Saf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43660</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43660</guid>
    <pubDate>Mon, 11 May 2026 21:19:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43660</strong></p>
  <p>A validation issue was addressed with improved logic. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43660">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43658 – The issue was addressed with improved memory handling. This issue is fixed in Sa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43658</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43658</guid>
    <pubDate>Mon, 11 May 2026 21:19:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43658</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43658">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43656 – An out-of-bounds write issue was addressed with improved input validation. This ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43656</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43656</guid>
    <pubDate>Mon, 11 May 2026 21:19:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43656</strong></p>
  <p>An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. Parsing a maliciously crafted file may lead to an unexpected app termination.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43656">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43655 – An out-of-bounds read was addressed with improved bounds checking. This issue is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43655</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43655</guid>
    <pubDate>Mon, 11 May 2026 21:19:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43655</strong></p>
  <p>An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination or read kernel memory.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43655">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43654 – The issue was addressed with improved memory handling. This issue is fixed in iO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43654</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43654</guid>
    <pubDate>Mon, 11 May 2026 21:19:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43654</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to disclose kernel memory.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-497</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43654">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28995 – A logic issue was addressed with improved restrictions. This issue is fixed in i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28995</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28995</guid>
    <pubDate>Mon, 11 May 2026 21:18:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28995</strong></p>
  <p>A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A malicious app may be able to break out of its sandbox.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28995">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28991 – An out-of-bounds read was addressed with improved bounds checking. This issue is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28991</guid>
    <pubDate>Mon, 11 May 2026 21:18:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28991</strong></p>
  <p>An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause a denial-of-service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28990 – The issue was addressed with improved memory handling. This issue is fixed in iO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28990</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28990</guid>
    <pubDate>Mon, 11 May 2026 21:18:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28990</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing a maliciously crafted image may corrupt process memory.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28990">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28987 – A logging issue was addressed with improved data redaction. This issue is fixed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28987</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28987</guid>
    <pubDate>Mon, 11 May 2026 21:18:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28987</strong></p>
  <p>A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to leak sensitive kernel state.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28987">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28986 – A race condition was addressed with additional validation. This issue is fixed i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28986</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28986</guid>
    <pubDate>Mon, 11 May 2026 21:18:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28986</strong></p>
  <p>A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28986">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28983 – A type confusion issue was addressed with improved checks. This issue is fixed i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28983</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28983</guid>
    <pubDate>Mon, 11 May 2026 21:18:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28983</strong></p>
  <p>A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A remote attacker may be able to cause a denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-843</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28983">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28974 – This issue was addressed with improved checks to prevent unauthorized actions. T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28974</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28974</guid>
    <pubDate>Mon, 11 May 2026 21:18:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28974</strong></p>
  <p>This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause a denial-of-service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28974">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28969 – A use after free issue was addressed with improved memory management. This issue...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28969</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28969</guid>
    <pubDate>Mon, 11 May 2026 21:18:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28969</strong></p>
  <p>A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28969">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28965 – A privacy issue was addressed with improved checks. This issue is fixed in iOS 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28965</guid>
    <pubDate>Mon, 11 May 2026 21:18:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28965</strong></p>
  <p>A privacy issue was addressed with improved checks. This issue is fixed in iOS 26.5 and iPadOS 26.5. A user may be able to view restricted content from the lock screen.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28964 – An inconsistent user interface issue was addressed with improved state managemen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28964</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28964</guid>
    <pubDate>Mon, 11 May 2026 21:18:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28964</strong></p>
  <p>An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 26.5 and iPadOS 26.5, visionOS 26.5. An app may be able to access sensitive user data.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-451</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28964">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28962 – This issue was addressed with improved access restrictions. This issue is fixed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28962</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28962</guid>
    <pubDate>Mon, 11 May 2026 21:18:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28962</strong></p>
  <p>This issue was addressed with improved access restrictions. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. Processing maliciously crafted web content may disclose sensitive user information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28962">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28959 – A buffer overflow was addressed with improved bounds checking. This issue is fix...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28959</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28959</guid>
    <pubDate>Mon, 11 May 2026 21:18:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28959</strong></p>
  <p>A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28959">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28955 – The issue was addressed with improved memory handling. This issue is fixed in Sa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28955</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28955</guid>
    <pubDate>Mon, 11 May 2026 21:18:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28955</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28955">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28954 – A file quarantine bypass was addressed with additional checks. This issue is fix...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28954</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28954</guid>
    <pubDate>Mon, 11 May 2026 21:18:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28954</strong></p>
  <p>A file quarantine bypass was addressed with additional checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A maliciously crafted disk image may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28954">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28953 – The issue was addressed with improved memory handling. This issue is fixed in Sa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28953</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28953</guid>
    <pubDate>Mon, 11 May 2026 21:18:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28953</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28953">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28952 – An integer overflow was addressed with improved input validation. This issue is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28952</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28952</guid>
    <pubDate>Mon, 11 May 2026 21:18:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28952</strong></p>
  <p>An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to cause unexpected system termination.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28952">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28951 – An authorization issue was addressed with improved state management. This issue ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28951</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28951</guid>
    <pubDate>Mon, 11 May 2026 21:18:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28951</strong></p>
  <p>An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to gain root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28951">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28947 – A use-after-free issue was addressed with improved memory management. This issue...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28947</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28947</guid>
    <pubDate>Mon, 11 May 2026 21:18:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28947</strong></p>
  <p>A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28947">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28944 – The issue was addressed with improved memory handling. This issue is fixed in Sa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28944</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28944</guid>
    <pubDate>Mon, 11 May 2026 21:18:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28944</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28944">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28943 – A logging issue was addressed with improved data redaction. This issue is fixed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28943</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28943</guid>
    <pubDate>Mon, 11 May 2026 21:18:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28943</strong></p>
  <p>A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to determine kernel memory layout.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28943">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28941 – The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28941</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28941</guid>
    <pubDate>Mon, 11 May 2026 21:18:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28941</strong></p>
  <p>The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Tahoe 26.5. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28941">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28940 – The issue was addressed with improved memory handling. This issue is fixed in iO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28940</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28940</guid>
    <pubDate>Mon, 11 May 2026 21:18:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28940</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5. Processing a maliciously crafted image may corrupt process memory.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28940">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28936 – The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28936</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28936</guid>
    <pubDate>Mon, 11 May 2026 21:18:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28936</strong></p>
  <p>The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sonoma 14.8.7, macOS Tahoe 26.5, visionOS 26.5. Processing a maliciously crafted file may lead to unexpected app termination.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28936">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28929 – A logic issue was addressed with improved checks. This issue is fixed in iOS 18...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28929</guid>
    <pubDate>Mon, 11 May 2026 21:18:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28929</strong></p>
  <p>A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. Replying to an email could display remote images in Mail in Lockdown Mode.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1254</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28913 – The issue was addressed with improved memory handling. This issue is fixed in Sa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28913</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28913</guid>
    <pubDate>Mon, 11 May 2026 21:18:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28913</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28913">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28907 – The issue was addressed with improved input validation. This issue is fixed in S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28907</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28907</guid>
    <pubDate>Mon, 11 May 2026 21:18:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28907</strong></p>
  <p>The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28907">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28906 – This issue was addressed through improved state management. This issue is fixed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28906</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28906</guid>
    <pubDate>Mon, 11 May 2026 21:18:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28906</strong></p>
  <p>This issue was addressed through improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, visionOS 26.5. An attacker may be able to track users through their IP address.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-359</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28906">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28905 – The issue was addressed with improved memory handling. This issue is fixed in Sa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28905</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28905</guid>
    <pubDate>Mon, 11 May 2026 21:18:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28905</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28905">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28904 – The issue was addressed with improved memory handling. This issue is fixed in Sa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28904</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28904</guid>
    <pubDate>Mon, 11 May 2026 21:18:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28904</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28904">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28883 – A use-after-free issue was addressed with improved memory management. This issue...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28883</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28883</guid>
    <pubDate>Mon, 11 May 2026 21:18:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28883</strong></p>
  <p>A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28883">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28873 – This issue was addressed with additional entitlement checks. This issue is fixed...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28873</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28873</guid>
    <pubDate>Mon, 11 May 2026 21:18:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28873</strong></p>
  <p>This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4. An app may be able to circumvent App Privacy Report logging.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28873">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28872 – A resource exhaustion issue was addressed with improved input validation. This i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28872</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28872</guid>
    <pubDate>Mon, 11 May 2026 21:18:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28872</strong></p>
  <p>A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4. A remote attacker may be able to cause a denial-of-service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28872">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28860 – The issue was addressed with improved input validation. This issue is fixed in i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28860</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28860</guid>
    <pubDate>Mon, 11 May 2026 21:18:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28860</strong></p>
  <p>The issue was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. A local attacker may be able to modify the state of the Keychain.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28860">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28847 – The issue was addressed with improved memory handling. This issue is fixed in Sa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28847</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28847</guid>
    <pubDate>Mon, 11 May 2026 21:18:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28847</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28847">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28846 – A buffer overflow was addressed with improved bounds checking. This issue is fix...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28846</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28846</guid>
    <pubDate>Mon, 11 May 2026 21:18:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28846</strong></p>
  <p>A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A remote attacker may be able to cause unexpected app termination.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28846">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47944 – memono Notepad 4.2 contains a denial of service vulnerability that allows attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47944</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47944</guid>
    <pubDate>Sun, 10 May 2026 13:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47944</strong></p>
  <p>memono Notepad 4.2 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character buffers into note fields. Attackers can generate a payload containing 350000 repeated characters and paste it twice into a new note to trigger an application crash on iOS devices.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47944">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7957 – Out of bounds write in Media in Google Chrome on Mac, iOS prior to 148.0.7778.96...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7957</guid>
    <pubDate>Wed, 06 May 2026 19:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7957</strong></p>
  <p>Out of bounds write in Media in Google Chrome on Mac, iOS prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7897 – Use after free in Mobile in Google Chrome on iOS prior to 148.0.7778.96 allowed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7897</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7897</guid>
    <pubDate>Wed, 06 May 2026 19:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7897</strong></p>
  <p>Use after free in Mobile in Google Chrome on iOS prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7897">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42090 – Notesnook is a note-taking app focused on user privacy &amp; ease of use. Prior to N...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42090</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42090</guid>
    <pubDate>Mon, 04 May 2026 17:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42090</strong></p>
  <p>Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Android version 3.3.20, a stored XSS vulnerability in the note export flow can be escalated to remote code execution in the desktop app. The root cause is that exported note fields such as title, headline, and content are inserted into the generated HTML t…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42090">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7361 – Use after free in iOS in Google Chrome prior to 147.0.7727.138 allowed a remote ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7361</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7361</guid>
    <pubDate>Tue, 28 Apr 2026 23:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7361</strong></p>
  <p>Use after free in iOS in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7361">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-43202 – This issue was addressed with improved memory handling. This issue is fixed in i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43202</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43202</guid>
    <pubDate>Thu, 02 Apr 2026 19:20:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-43202</strong></p>
  <p>This issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6. Processing a file may lead to memory corruption.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43202">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33976 – Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33976</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33976</guid>
    <pubDate>Fri, 27 Mar 2026 22:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33976</strong></p>
  <p>Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can be escalated to remote code execution in the desktop app. The root cause is that the clipper preserves attacker-controlled attributes from the source page’s root element and stores them inside web-clip HTML. When the clip is later opened, Notesnook r…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33976">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20125 – A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS X...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20125</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20125</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20125</strong></p>
  <p>A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3E could allow an authenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending malformed HTTP re…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-228</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20125">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20086 – A vulnerability in the processing of Control and Provisioning of Wireless Access...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20086</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20086</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20086</strong></p>
  <p>A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) packets of Cisco IOS XE Wireless Controller Software for the Catalyst CW9800 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability is due to improper handling of a malformed CAPWAP packet. An attacker could expl…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-230</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20086">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20084 – A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20084</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20084</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20084</strong></p>
  <p>A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause BOOTP packets to be forwarded between VLANs, resulting in a denial of service (DoS) condition.   This vulnerability is due to improper handling of BOOTP packets on Cisco Catalyst 9000 Series Switches. An attacker could exploit this vulnerability by sending BOOTP request…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20084">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20012 – A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20012</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20012</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20012</strong></p>
  <p>A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak, resulting in a denial of service (DoS) condition on an affected device.  This vulner…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20012">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20004 – A vulnerability in the TLS library of Cisco IOS XE Software could allow an unaut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20004</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20004</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20004</strong></p>
  <p>A vulnerability in the TLS library of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust the available memory of an affected device.  This vulnerability is due to improper management of memory resources during TLS connection setup. An attacker could exploit this vulnerability by repeatedly triggering the conditions that cause the memory increase. This could be do…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-771</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20004">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28894 – A denial-of-service issue was addressed with improved input validation. This iss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28894</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28894</guid>
    <pubDate>Wed, 25 Mar 2026 01:17:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28894</strong></p>
  <p>A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. A remote attacker may be able to cause a denial-of-service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28894">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28876 – A parsing issue in the handling of directory paths was addressed with improved p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28876</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28876</guid>
    <pubDate>Wed, 25 Mar 2026 01:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28876</strong></p>
  <p>A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4. An app may be able to access sensitive user data.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28876">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28875 – A buffer overflow was addressed with improved bounds checking. This issue is fix...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28875</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28875</guid>
    <pubDate>Wed, 25 Mar 2026 01:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28875</strong></p>
  <p>A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote attacker may be able to cause a denial-of-service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28875">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28874 – The issue was addressed with improved checks. This issue is fixed in iOS 26.4 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28874</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28874</guid>
    <pubDate>Wed, 25 Mar 2026 01:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28874</strong></p>
  <p>The issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote attacker may cause an unexpected app termination.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28874">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28865 – An authentication issue was addressed with improved state management. This issue...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28865</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28865</guid>
    <pubDate>Wed, 25 Mar 2026 01:17:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28865</strong></p>
  <p>An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An attacker in a privileged network position may be able to intercept network traffic.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28865">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-28858 – A buffer overflow was addressed with improved bounds checking. This issue is fix...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28858</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28858</guid>
    <pubDate>Wed, 25 Mar 2026 01:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-28858</strong></p>
  <p>A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote user may be able to cause unexpected system termination or corrupt kernel memory.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28858">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28855 – A permissions issue was addressed with additional restrictions. This issue is fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28855</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28855</guid>
    <pubDate>Wed, 25 Mar 2026 01:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28855</strong></p>
  <p>A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3. An app may be able to access protected user data.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28855">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20698 – The issue was addressed with improved memory handling. This issue is fixed in iO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20698</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20698</guid>
    <pubDate>Wed, 25 Mar 2026 01:17:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20698</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to cause unexpected system termination or corrupt kernel memory.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20698">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-20688 – A path handling issue was addressed with improved validation. This issue is fixe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20688</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20688</guid>
    <pubDate>Wed, 25 Mar 2026 01:17:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-20688</strong></p>
  <p>A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4. An app may be able to break out of its sandbox.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20688">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20687 – A use after free issue was addressed with improved memory management. This issue...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20687</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20687</guid>
    <pubDate>Wed, 25 Mar 2026 01:17:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20687</strong></p>
  <p>A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Tahoe 26.4, tvOS 26.4, watchOS 26.4. An app may be able to cause unexpected system termination or write kernel memory.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20687">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32318 – Cryptomator for IOS offers multi-platform transparent client-side encryption for...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32318</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32318</guid>
    <pubDate>Fri, 20 Mar 2026 19:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32318</strong></p>
  <p>Cryptomator for IOS offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 2.8.3, an integrity check vulnerability allows an attacker tamper with the vault configuration file leading to a man-in-the-middle vulnerability in Hub key loading mechanism. Before this fix, the client trusted endpoints from the vault config without host authenticity checks, whic…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32318">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-43010 – The issue was addressed with improved memory handling. This issue is fixed in iO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-43010</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-43010</guid>
    <pubDate>Thu, 12 Mar 2026 01:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-43010</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS 16.7.15, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43010">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-31852 – Jellyfin is an open-source media system. The code-quality.yml GitHub Actions wor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31852</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31852</guid>
    <pubDate>Wed, 11 Mar 2026 17:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-31852</strong></p>
  <p>Jellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulnerable to arbitrary code execution via pull requests from forked repositories. Due to the workflow's elevated permissions (nearly all write permissions), this vulnerability enables full repository takeover of jellyfin/jellyfin-ios, exfiltration of highly privileged secrets, Apple…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31852">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20074 – A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) multi-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20074</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20074</guid>
    <pubDate>Wed, 11 Mar 2026 17:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20074</strong></p>
  <p>A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) multi-instance routing feature of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the IS-IS process to restart unexpectedly.  This vulnerability is due to insufficient input validation of ingress IS-IS packets. An attacker could exploit this vulnerability by sending crafted IS-IS packets t…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-1287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20074">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20046 – A vulnerability in task group assignment for a specific CLI command in Cisco IOS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20046</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20046</guid>
    <pubDate>Wed, 11 Mar 2026 17:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20046</strong></p>
  <p>A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges and gain full administrative control of an affected device.  This vulnerability is due to incorrect mapping of a command to task groups within the source code. An attacker with a low-privileged account could exploit this vulnerability by…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20046">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20040 – A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20040</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20040</guid>
    <pubDate>Wed, 11 Mar 2026 17:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20040</strong></p>
  <p>A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device.  This vulnerability is due to insufficient validation of user arguments that are passed to specific CLI commands. An attacker with a low-privileged account could exploit this vulnerability by using crafte…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20040">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30798 – Insufficient Verification of Data Authenticity, Improper Handling of Exceptional...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30798</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30798</guid>
    <pubDate>Thu, 05 Mar 2026 16:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30798</strong></p>
  <p>Insufficient Verification of Data Authenticity, Improper Handling of Exceptional Conditions vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop, strategy processing modules) allows Protocol Manipulation. This vulnerability is associated with program files src/hbbs_http/sync.Rs and program routines stop-service handler in hea…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30798">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30797 – Missing Authorization vulnerability in rustdesk-client RustDesk Client rustdesk-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30797</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30797</guid>
    <pubDate>Thu, 05 Mar 2026 16:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30797</strong></p>
  <p>Missing Authorization vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, config import modules) allows Application API Message Manipulation via Man-in-the-Middle. This vulnerability is associated with program files flutter/lib/common.Dart and program routines importConfig() via URI handler.  This issue affects RustD…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-749</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30797">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30795 – Cleartext Transmission of Sensitive Information vulnerability in rustdesk-client...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30795</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30795</guid>
    <pubDate>Thu, 05 Mar 2026 16:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30795</strong></p>
  <p>Cleartext Transmission of Sensitive Information vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop modules) allows Sniffing Attacks. This vulnerability is associated with program files src/hbbs_http/sync.Rs and program routines Heartbeat JSON payload construction (preset-address-book-password).  This issue affects RustDesk…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30795">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30794 – Improper Certificate Validation vulnerability in rustdesk-client RustDesk Client...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30794</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30794</guid>
    <pubDate>Thu, 05 Mar 2026 16:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30794</strong></p>
  <p>Improper Certificate Validation vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (HTTP API client, TLS transport modules) allows Adversary in the Middle (AiTM). This vulnerability is associated with program files src/hbbs_http/http_client.Rs and program routines TLS retry with danger_accept_invalid_certs(true).  This issue affects RustDesk Cl…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30794">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-30793 – Cross-Site Request Forgery (CSRF) vulnerability in rustdesk-client RustDesk Clie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30793</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30793</guid>
    <pubDate>Thu, 05 Mar 2026 16:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-30793</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, FFI bridge modules) allows Privilege Escalation. This vulnerability is associated with program files flutter/lib/common.Dart, src/flutter_ffi.Rs and program routines URI handler for rustdesk://password/, bind.MainSetPermanentPasswor…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30793">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30792 – A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, M...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30792</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30792</guid>
    <pubDate>Thu, 05 Mar 2026 16:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30792</strong></p>
  <p>A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Strategy sync, HTTP API client, config options engine modules) allows Application API Message Manipulation via Man-in-the-Middle. This vulnerability is associated with program files src/hbbs_http/sync.Rs, hbb_common/src/config.Rs and program routines Strategy merge loop in sync.Rs…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-657</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30792">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-30789 – Authentication Bypass by Capture-replay, Use of Password Hash With Insufficient ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30789</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30789</guid>
    <pubDate>Thu, 05 Mar 2026 16:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-30789</strong></p>
  <p>Authentication Bypass by Capture-replay, Use of Password Hash With Insufficient Computational Effort vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Client login, peer authentication modules) allows Reusing Session IDs (aka Session Replay). This vulnerability is associated with program files src/client.Rs and program routines hash_password(…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-294</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30789">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-30783 – A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, M...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30783</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30783</guid>
    <pubDate>Thu, 05 Mar 2026 16:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-30783</strong></p>
  <p>A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Client signaling, API sync loop, config management modules) allows Privilege Abuse. This vulnerability is associated with program files src/rendezvous_mediator.Rs, src/hbbs_http/sync.Rs and program routines API sync loop, api-server config handling.  This issue affects RustDesk Cl…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-602</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30783">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30791 – Use of a Broken or Risky Cryptographic Algorithm vulnerability in rustdesk-clien...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30791</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30791</guid>
    <pubDate>Thu, 05 Mar 2026 15:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30791</strong></p>
  <p>Use of a Broken or Risky Cryptographic Algorithm vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Config import, URI scheme handler, CLI --config modules) allows Retrieve Embedded Sensitive Data. This vulnerability is associated with program files flutter/lib/common.Dart, hbb_common/src/config.Rs and program routines parseRustdesk…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30791">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-2634 – Malicious scripts could cause desynchronization between the address bar and web ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2634</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2634</guid>
    <pubDate>Tue, 24 Feb 2026 14:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-2634</strong></p>
  <p>Malicious scripts could cause desynchronization between the address bar and web content before a response is received in Firefox iOS, allowing attacker-controlled pages to be presented under spoofed domains. This vulnerability was fixed in Firefox for iOS 147.4.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-451</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2634">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25354 – iSmartViewPro 1.3.34 contains a denial of service vulnerability that allows atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25354</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25354</guid>
    <pubDate>Wed, 18 Feb 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25354</strong></p>
  <p>iSmartViewPro 1.3.34 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the camera ID input field. Attackers can paste a 257-character buffer into the camera DID and password fields to trigger an application crash on iOS devices.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25354">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25349 – ScadaApp for iOS 1.1.4.0 contains a denial of service vulnerability that allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25349</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25349</guid>
    <pubDate>Wed, 18 Feb 2026 22:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25349</strong></p>
  <p>ScadaApp for iOS 1.1.4.0 contains a denial of service vulnerability that allows attackers to crash the application by inputting an oversized buffer in the Servername field. Attackers can paste a 257-character buffer during login to trigger an application crash on iOS devices.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25349">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25341 – iNetTools for iOS 8.20 contains a denial of service vulnerability in the Whois f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25341</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25341</guid>
    <pubDate>Thu, 12 Feb 2026 23:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25341</strong></p>
  <p>iNetTools for iOS 8.20 contains a denial of service vulnerability in the Whois feature that allows attackers to crash the application by manipulating input. Attackers can paste a specially crafted 98-character buffer into the Domain Name field to trigger an application crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25341">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25339 – GHIA CamIP 1.2 for iOS contains a denial of service vulnerability in the passwor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25339</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25339</guid>
    <pubDate>Thu, 12 Feb 2026 23:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25339</strong></p>
  <p>GHIA CamIP 1.2 for iOS contains a denial of service vulnerability in the password input field that allows attackers to crash the application. Attackers can paste a 33-character buffer of repeated characters into the password field to trigger an application crash on iOS devices.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25339">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20700 – A memory corruption issue was addressed with improved state management. This iss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20700</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20700</guid>
    <pubDate>Wed, 11 Feb 2026 23:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20700</strong></p>
  <p>A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individual…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20700">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-20677 – A race condition was addressed with improved handling of symbolic links. This is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20677</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20677</guid>
    <pubDate>Wed, 11 Feb 2026 23:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-20677</strong></p>
  <p>A race condition was addressed with improved handling of symbolic links. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. A shortcut may be able to bypass sandbox restrictions.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20677">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20667 – A logic issue was addressed with improved checks. This issue is fixed in iOS 26...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20667</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20667</guid>
    <pubDate>Wed, 11 Feb 2026 23:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20667</strong></p>
  <p>A logic issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, watchOS 26.3. An app may be able to break out of its sandbox.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20667">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20660 – A path handling issue was addressed with improved logic. This issue is fixed in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20660</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20660</guid>
    <pubDate>Wed, 11 Feb 2026 23:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20660</strong></p>
  <p>A path handling issue was addressed with improved logic. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.5, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. A remote user may be able to write arbitrary files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20660">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20652 – The issue was addressed with improved memory handling. This issue is fixed in Sa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20652</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20652</guid>
    <pubDate>Wed, 11 Feb 2026 23:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20652</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. A remote attacker may be able to cause a denial-of-service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20652">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20650 – A denial-of-service issue was addressed with improved validation. This issue is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20650</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20650</guid>
    <pubDate>Wed, 11 Feb 2026 23:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20650</strong></p>
  <p>A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker in a privileged network position may be able to perform denial-of-service attack using crafted Bluetooth packets.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20650">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20649 – A logging issue was addressed with improved data redaction. This issue is fixed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20649</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20649</guid>
    <pubDate>Wed, 11 Feb 2026 23:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20649</strong></p>
  <p>A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, watchOS 26.3. A user may be able to view sensitive user information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-377</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20649">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20641 – A privacy issue was addressed with improved checks. This issue is fixed in iOS 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20641</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20641</guid>
    <pubDate>Wed, 11 Feb 2026 23:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20641</strong></p>
  <p>A privacy issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to identify what other apps a user has installed.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20641">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20628 – A permissions issue was addressed with additional restrictions. This issue is fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20628</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20628</guid>
    <pubDate>Wed, 11 Feb 2026 23:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20628</strong></p>
  <p>A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to break out of its sandbox.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20628">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20626 – This issue was addressed with improved checks. This issue is fixed in iOS 26.3 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20626</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20626</guid>
    <pubDate>Wed, 11 Feb 2026 23:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20626</strong></p>
  <p>This issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Tahoe 26.3, visionOS 26.3. A malicious app may be able to gain root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20626">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
