<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Apple macOS (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/macos.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/macos-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Apple macOS (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:40 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-49237 – An issue was discovered in Canonical Multipass for macOS before version 1.16.3 d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49237</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49237</guid>
    <pubDate>Thu, 28 May 2026 14:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49237</strong></p>
  <p>An issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-5199. While the patch in version 1.16.0 updated the ownership of the multipassd daemon binary to root:wheel, five co-located binaries (multipass, qemu-img, qemu-system-aarch64, qemu-system-x86_64, and sshfs_server) in /Library/Application Support/com.canonical.multipass/bin/ retain…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49237">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46284 – A race condition was addressed with additional validation. This issue is fixed i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46284</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46284</guid>
    <pubDate>Tue, 26 May 2026 22:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46284</strong></p>
  <p>A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An app may be able to gain root privileges.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46284">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-43306 – A logic issue was addressed with improved checks. This issue is fixed in macOS S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43306</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43306</guid>
    <pubDate>Tue, 26 May 2026 22:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-43306</strong></p>
  <p>A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A malicious app may be able to gain root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43306">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9560 – Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9560</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9560</guid>
    <pubDate>Tue, 26 May 2026 18:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9560</strong></p>
  <p>Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9560">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5843 – The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM librar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5843</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5843</guid>
    <pubDate>Fri, 22 May 2026 20:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5843</strong></p>
  <p>The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configuration field in config.json. When a model's config.json specifies a model_file pointing to a Python file, MLX-LM uses importlib to load and execute it with no trust_remote_code gate or equivalent safet…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-829</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5843">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5817 – The vllm-metal inference backend in Docker Model Runner on macOS unconditionally...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5817</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5817</guid>
    <pubDate>Fri, 22 May 2026 20:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5817</strong></p>
  <p>The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This causes transformers.AutoTokenizer.from_pretrained() to import and execute arbitrary Python files included in any model pulled from an OCI registry, resulting in arbitrary code execution on the Docker host as the Docker Deskto…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-829</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5817">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47114 – IINA before 1.4.3 contains a user-assisted command execution vulnerability that ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47114</guid>
    <pubDate>Thu, 21 May 2026 20:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47114</strong></p>
  <p>IINA before 1.4.3 contains a user-assisted command execution vulnerability that allows remote attackers to execute arbitrary commands by supplying malicious mpv_-prefixed query parameters through the iina://open custom URL scheme handler. Attackers can deliver a crafted URL via a browser that passes unvalidated mpv_options/input-commands parameters into the mpv runtime, causing arbitrary command…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32323 – Mullvad VPN is a VPN client app for desktop and mobile. When using macOS with ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32323</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32323</guid>
    <pubDate>Tue, 19 May 2026 02:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32323</strong></p>
  <p>Mullvad VPN is a VPN client app for desktop and mobile. When using macOS with versions 2026.1 and below, Mullvad VPN may allow local privilege escalation during installation or upgrade. The installer package executes binaries from /Applications/Mullvad VPN.app without verifying if the bundle is attacker-controlled or that the path is the legitimate Mullvad application. A user in the admin group c…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32323">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-26191 – Fleet is open source device management software. Prior to version 4.81.0, a vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26191</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26191</guid>
    <pubDate>Thu, 14 May 2026 20:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-26191</strong></p>
  <p>Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet's software installer pipeline could allow a crafted software package to execute arbitrary commands as root (macOS/Linux) or SYSTEM (Windows) on managed endpoints when an uninstall is triggered. When a software package (.pkg, .deb, .rpm, .exe, or .msi) is uploaded to Fleet, metadata is extracted from…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26191">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0236 – A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0236</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0236</guid>
    <pubDate>Wed, 13 May 2026 19:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0236</strong></p>
  <p>A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its AppleScript interface allowing a locally authenticated non-admin user to leverage this exposed Apple Event handler to send unauthorized commands to the browser.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0236">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0237 – An improper protection of alternate path vulnerability in Palo Alto Networks Pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0237</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0237</guid>
    <pubDate>Wed, 13 May 2026 18:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0237</strong></p>
  <p>An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allows a locally authenticated non-admin user to leverage an exposed communication channel to send unauthorized commands to the browser, bypassing security controls.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-424</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0237">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-43524 – An access issue was addressed with additional sandbox restrictions. This issue i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43524</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43524</guid>
    <pubDate>Tue, 12 May 2026 18:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-43524</strong></p>
  <p>An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.2. An app may be able to break out of its sandbox.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43524">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43668 – A use after free issue was addressed with improved memory management. This issue...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43668</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43668</guid>
    <pubDate>Mon, 11 May 2026 21:19:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43668</strong></p>
  <p>A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43668">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43661 – A buffer overflow issue was addressed with improved memory handling. This issue ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43661</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43661</guid>
    <pubDate>Mon, 11 May 2026 21:19:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43661</strong></p>
  <p>A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. Processing a maliciously crafted image may corrupt process memory.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43661">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43660 – A validation issue was addressed with improved logic. This issue is fixed in Saf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43660</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43660</guid>
    <pubDate>Mon, 11 May 2026 21:19:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43660</strong></p>
  <p>A validation issue was addressed with improved logic. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43660">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43658 – The issue was addressed with improved memory handling. This issue is fixed in Sa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43658</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43658</guid>
    <pubDate>Mon, 11 May 2026 21:19:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43658</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43658">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43656 – An out-of-bounds write issue was addressed with improved input validation. This ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43656</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43656</guid>
    <pubDate>Mon, 11 May 2026 21:19:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43656</strong></p>
  <p>An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. Parsing a maliciously crafted file may lead to an unexpected app termination.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43656">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43655 – An out-of-bounds read was addressed with improved bounds checking. This issue is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43655</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43655</guid>
    <pubDate>Mon, 11 May 2026 21:19:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43655</strong></p>
  <p>An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination or read kernel memory.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43655">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43654 – The issue was addressed with improved memory handling. This issue is fixed in iO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43654</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43654</guid>
    <pubDate>Mon, 11 May 2026 21:19:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43654</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to disclose kernel memory.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-497</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43654">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43652 – A permissions issue was addressed with additional restrictions. This issue is fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43652</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43652</guid>
    <pubDate>Mon, 11 May 2026 21:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43652</strong></p>
  <p>A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.5. An app may be able to access protected user data.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43652">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39871 – A path handling issue was addressed with improved logic. This issue is fixed in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39871</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39871</guid>
    <pubDate>Mon, 11 May 2026 21:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39871</strong></p>
  <p>A path handling issue was addressed with improved logic. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to observe unprotected user data.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-552</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39871">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39870 – The issue was addressed with improved memory handling. This issue is fixed in ma...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39870</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39870</guid>
    <pubDate>Mon, 11 May 2026 21:18:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39870</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. Processing a maliciously crafted image may corrupt process memory.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39870">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28995 – A logic issue was addressed with improved restrictions. This issue is fixed in i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28995</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28995</guid>
    <pubDate>Mon, 11 May 2026 21:18:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28995</strong></p>
  <p>A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A malicious app may be able to break out of its sandbox.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28995">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28991 – An out-of-bounds read was addressed with improved bounds checking. This issue is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28991</guid>
    <pubDate>Mon, 11 May 2026 21:18:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28991</strong></p>
  <p>An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause a denial-of-service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28990 – The issue was addressed with improved memory handling. This issue is fixed in iO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28990</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28990</guid>
    <pubDate>Mon, 11 May 2026 21:18:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28990</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing a maliciously crafted image may corrupt process memory.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28990">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28987 – A logging issue was addressed with improved data redaction. This issue is fixed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28987</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28987</guid>
    <pubDate>Mon, 11 May 2026 21:18:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28987</strong></p>
  <p>A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to leak sensitive kernel state.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28987">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28986 – A race condition was addressed with additional validation. This issue is fixed i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28986</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28986</guid>
    <pubDate>Mon, 11 May 2026 21:18:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28986</strong></p>
  <p>A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28986">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28983 – A type confusion issue was addressed with improved checks. This issue is fixed i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28983</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28983</guid>
    <pubDate>Mon, 11 May 2026 21:18:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28983</strong></p>
  <p>A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A remote attacker may be able to cause a denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-843</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28983">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28978 – A permissions issue was addressed with additional restrictions. This issue is fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28978</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28978</guid>
    <pubDate>Mon, 11 May 2026 21:18:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28978</strong></p>
  <p>A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A malicious app may be able to break out of its sandbox.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28978">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28976 – An information leakage was addressed with additional validation. This issue is f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28976</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28976</guid>
    <pubDate>Mon, 11 May 2026 21:18:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28976</strong></p>
  <p>An information leakage was addressed with additional validation. This issue is fixed in macOS Tahoe 26.5. An app may be able to gain root privileges.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28976">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28974 – This issue was addressed with improved checks to prevent unauthorized actions. T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28974</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28974</guid>
    <pubDate>Mon, 11 May 2026 21:18:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28974</strong></p>
  <p>This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause a denial-of-service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28974">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28969 – A use after free issue was addressed with improved memory management. This issue...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28969</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28969</guid>
    <pubDate>Mon, 11 May 2026 21:18:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28969</strong></p>
  <p>A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28969">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28962 – This issue was addressed with improved access restrictions. This issue is fixed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28962</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28962</guid>
    <pubDate>Mon, 11 May 2026 21:18:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28962</strong></p>
  <p>This issue was addressed with improved access restrictions. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. Processing maliciously crafted web content may disclose sensitive user information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28962">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28959 – A buffer overflow was addressed with improved bounds checking. This issue is fix...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28959</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28959</guid>
    <pubDate>Mon, 11 May 2026 21:18:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28959</strong></p>
  <p>A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28959">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28955 – The issue was addressed with improved memory handling. This issue is fixed in Sa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28955</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28955</guid>
    <pubDate>Mon, 11 May 2026 21:18:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28955</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28955">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28954 – A file quarantine bypass was addressed with additional checks. This issue is fix...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28954</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28954</guid>
    <pubDate>Mon, 11 May 2026 21:18:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28954</strong></p>
  <p>A file quarantine bypass was addressed with additional checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A maliciously crafted disk image may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28954">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28953 – The issue was addressed with improved memory handling. This issue is fixed in Sa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28953</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28953</guid>
    <pubDate>Mon, 11 May 2026 21:18:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28953</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28953">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28952 – An integer overflow was addressed with improved input validation. This issue is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28952</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28952</guid>
    <pubDate>Mon, 11 May 2026 21:18:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28952</strong></p>
  <p>An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to cause unexpected system termination.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28952">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28951 – An authorization issue was addressed with improved state management. This issue ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28951</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28951</guid>
    <pubDate>Mon, 11 May 2026 21:18:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28951</strong></p>
  <p>An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to gain root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28951">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28947 – A use-after-free issue was addressed with improved memory management. This issue...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28947</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28947</guid>
    <pubDate>Mon, 11 May 2026 21:18:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28947</strong></p>
  <p>A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28947">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28944 – The issue was addressed with improved memory handling. This issue is fixed in Sa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28944</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28944</guid>
    <pubDate>Mon, 11 May 2026 21:18:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28944</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28944">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28943 – A logging issue was addressed with improved data redaction. This issue is fixed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28943</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28943</guid>
    <pubDate>Mon, 11 May 2026 21:18:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28943</strong></p>
  <p>A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to determine kernel memory layout.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28943">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28941 – The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28941</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28941</guid>
    <pubDate>Mon, 11 May 2026 21:18:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28941</strong></p>
  <p>The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Tahoe 26.5. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28941">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28940 – The issue was addressed with improved memory handling. This issue is fixed in iO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28940</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28940</guid>
    <pubDate>Mon, 11 May 2026 21:18:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28940</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5. Processing a maliciously crafted image may corrupt process memory.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28940">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28936 – The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28936</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28936</guid>
    <pubDate>Mon, 11 May 2026 21:18:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28936</strong></p>
  <p>The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sonoma 14.8.7, macOS Tahoe 26.5, visionOS 26.5. Processing a maliciously crafted file may lead to unexpected app termination.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28936">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28930 – A permissions issue was addressed with additional restrictions. This issue is fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28930</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28930</guid>
    <pubDate>Mon, 11 May 2026 21:18:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28930</strong></p>
  <p>A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.5. An app may be able to access protected user data.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28930">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28929 – A logic issue was addressed with improved checks. This issue is fixed in iOS 18...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28929</guid>
    <pubDate>Mon, 11 May 2026 21:18:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28929</strong></p>
  <p>A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. Replying to an email could display remote images in Mail in Lockdown Mode.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1254</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28925 – A buffer overflow was addressed with improved bounds checking. This issue is fix...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28925</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28925</guid>
    <pubDate>Mon, 11 May 2026 21:18:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28925</strong></p>
  <p>A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to cause unexpected system termination or write kernel memory.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28925">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28924 – A race condition was addressed with improved handling of symbolic links. This is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28924</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28924</guid>
    <pubDate>Mon, 11 May 2026 21:18:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28924</strong></p>
  <p>A race condition was addressed with improved handling of symbolic links. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to access Contacts without user consent.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28924">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28923 – A logging issue was addressed with improved data redaction. This issue is fixed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28923</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28923</guid>
    <pubDate>Mon, 11 May 2026 21:18:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28923</strong></p>
  <p>A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A malicious app may be able to break out of its sandbox.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28923">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28919 – A consistency issue was addressed with improved state handling. This issue is fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28919</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28919</guid>
    <pubDate>Mon, 11 May 2026 21:18:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28919</strong></p>
  <p>A consistency issue was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to gain root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28919">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28915 – A parsing issue in the handling of directory paths was addressed with improved p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28915</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28915</guid>
    <pubDate>Mon, 11 May 2026 21:18:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28915</strong></p>
  <p>A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to gain root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28915">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28913 – The issue was addressed with improved memory handling. This issue is fixed in Sa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28913</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28913</guid>
    <pubDate>Mon, 11 May 2026 21:18:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28913</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28913">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28908 – A denial of service issue was addressed by removing the vulnerable code. This is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28908</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28908</guid>
    <pubDate>Mon, 11 May 2026 21:18:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28908</strong></p>
  <p>A denial of service issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to modify protected parts of the file system.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28908">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28907 – The issue was addressed with improved input validation. This issue is fixed in S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28907</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28907</guid>
    <pubDate>Mon, 11 May 2026 21:18:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28907</strong></p>
  <p>The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28907">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28906 – This issue was addressed through improved state management. This issue is fixed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28906</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28906</guid>
    <pubDate>Mon, 11 May 2026 21:18:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28906</strong></p>
  <p>This issue was addressed through improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, visionOS 26.5. An attacker may be able to track users through their IP address.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-359</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28906">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28905 – The issue was addressed with improved memory handling. This issue is fixed in Sa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28905</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28905</guid>
    <pubDate>Mon, 11 May 2026 21:18:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28905</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28905">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28904 – The issue was addressed with improved memory handling. This issue is fixed in Sa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28904</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28904</guid>
    <pubDate>Mon, 11 May 2026 21:18:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28904</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28904">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28883 – A use-after-free issue was addressed with improved memory management. This issue...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28883</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28883</guid>
    <pubDate>Mon, 11 May 2026 21:18:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28883</strong></p>
  <p>A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28883">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28860 – The issue was addressed with improved input validation. This issue is fixed in i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28860</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28860</guid>
    <pubDate>Mon, 11 May 2026 21:18:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28860</strong></p>
  <p>The issue was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. A local attacker may be able to modify the state of the Keychain.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28860">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28848 – A buffer overflow was addressed with improved bounds checking. This issue is fix...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28848</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28848</guid>
    <pubDate>Mon, 11 May 2026 21:18:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28848</strong></p>
  <p>A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Tahoe 26.5. A remote attacker may be able to cause unexpected system termination.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28848">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28847 – The issue was addressed with improved memory handling. This issue is fixed in Sa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28847</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28847</guid>
    <pubDate>Mon, 11 May 2026 21:18:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28847</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28847">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28846 – A buffer overflow was addressed with improved bounds checking. This issue is fix...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28846</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28846</guid>
    <pubDate>Mon, 11 May 2026 21:18:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28846</strong></p>
  <p>A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A remote attacker may be able to cause unexpected app termination.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28846">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28840 – A permissions issue was addressed with additional restrictions. This issue is fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28840</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28840</guid>
    <pubDate>Mon, 11 May 2026 21:18:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28840</strong></p>
  <p>A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.4. An app may be able to gain root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28840">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34354 – Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34354</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34354</guid>
    <pubDate>Fri, 08 May 2026 16:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34354</strong></p>
  <p>Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escalation. The GPA service creates an IPC socket in the world-writable /tmp directory. It accepts unauthenticated IPC control messages. This enables a TOCTOU vulnerability in the HandleSaveLogs() function of the GPA service, by creating a log file and manipulating it into a symlink…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34354">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40599 – ClearanceKit intercepts file-system access events on macOS and enforces per-proc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40599</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40599</guid>
    <pubDate>Tue, 21 Apr 2026 18:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40599</strong></p>
  <p>ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.5, ClearanceKit incorrectly treats a process with an empty Team ID and a non-empty Signing ID as an Apple platform binary. This bug allows a malicious software to impersonate an apple process in the global allowlist, and access all protected files. This vulnerability is fixed in 5.0.5.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40599">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33092 – Local privilege escalation due to improper handling of environment variables. Th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33092</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33092</guid>
    <pubDate>Fri, 10 Apr 2026 14:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33092</strong></p>
  <p>Local privilege escalation due to improper handling of environment variables. The following products are affected: Acronis True Image OEM (macOS) before build 42571, Acronis True Image (macOS) before build 42902.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-15</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33092">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-39860 – Nix is a package manager for Linux and other Unix systems. A bug in the fix for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39860</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39860</guid>
    <pubDate>Wed, 08 Apr 2026 21:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-39860</strong></p>
  <p>Nix is a package manager for Linux and other Unix systems. A bug in the fix for CVE-2024-27297 allowed for arbitrary overwrites of files writable by the Nix process orchestrating the builds (typically the Nix daemon running as root in multi-user installations) by following symlinks during fixed-output derivation output registration. This affects sandboxed Linux builds - sandboxed macOS builds are…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-61</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39860">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39862 – Tophat is a mobile applications testing harness. Prior to 2.5.1, Tophat is affec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39862</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39862</guid>
    <pubDate>Wed, 08 Apr 2026 20:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39862</strong></p>
  <p>Tophat is a mobile applications testing harness. Prior to 2.5.1, Tophat is affected by remote code execution via crafted tophat:// or http://localhost:29070 URLs. The arguments query parameter flows unsanitized from URL parsing through to /bin/bash -c execution, allowing an attacker to execute arbitrary commands on a developer's macOS workstation. Any developer with Tophat installed is vulnerable…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39862">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34770 – Electron is a framework for writing cross-platform desktop applications using Ja...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34770</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34770</guid>
    <pubDate>Sat, 04 Apr 2026 00:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34770</strong></p>
  <p>Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, apps that use the powerMonitor module may be vulnerable to a use-after-free. After the native PowerMonitor object is garbage-collected, the associated OS-level resources (a message window on Windows, a shutdown handler on macOS) retai…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34770">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-28373 – The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28373</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28373</guid>
    <pubDate>Fri, 03 Apr 2026 17:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-28373</strong></p>
  <p>The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when processing the filePath property. A malicious export can write arbitrary content to any path on the victim's filesystem.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28373">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-43264 – The issue was addressed with improved memory handling. This issue is fixed in ma...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43264</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43264</guid>
    <pubDate>Thu, 02 Apr 2026 19:20:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-43264</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may corrupt process memory.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43264">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-43257 – This issue was addressed with improved handling of symlinks. This issue is fixed...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43257</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43257</guid>
    <pubDate>Thu, 02 Apr 2026 19:20:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-43257</strong></p>
  <p>This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.6. An app may be able to break out of its sandbox.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43257">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-43219 – The issue was addressed with improved memory handling. This issue is fixed in ma...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43219</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43219</guid>
    <pubDate>Thu, 02 Apr 2026 19:20:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-43219</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may corrupt process memory.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43219">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-43202 – This issue was addressed with improved memory handling. This issue is fixed in i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43202</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43202</guid>
    <pubDate>Thu, 02 Apr 2026 19:20:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-43202</strong></p>
  <p>This issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6. Processing a file may lead to memory corruption.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43202">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-44303 – The issue was addressed with improved checks. This issue is fixed in macOS Sequo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-44303</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-44303</guid>
    <pubDate>Thu, 02 Apr 2026 19:18:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-44303</strong></p>
  <p>The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1. A malicious application may be able to modify protected parts of the file system.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-44303">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-44286 – This issue was addressed through improved state management. This issue is fixed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-44286</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-44286</guid>
    <pubDate>Thu, 02 Apr 2026 19:18:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-44286</strong></p>
  <p>This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with physical access can input keyboard events to apps running on a locked device.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-44286">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-44250 – A permissions issue was addressed with additional restrictions. This issue is fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-44250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-44250</guid>
    <pubDate>Thu, 02 Apr 2026 19:18:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-44250</strong></p>
  <p>A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-44250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-44219 – A permissions issue was addressed with additional restrictions. This issue is fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-44219</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-44219</guid>
    <pubDate>Thu, 02 Apr 2026 19:18:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-44219</strong></p>
  <p>A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. A malicious application with root privileges may be able to access private information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-44219">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-40858 – A permissions issue was addressed with additional restrictions. This issue is fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-40858</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-40858</guid>
    <pubDate>Thu, 02 Apr 2026 19:17:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-40858</strong></p>
  <p>A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be able to access Contacts without user consent.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40858">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-40849 – A race condition was addressed with additional validation. This issue is fixed i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-40849</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-40849</guid>
    <pubDate>Thu, 02 Apr 2026 19:17:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-40849</strong></p>
  <p>A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.1. An app may be able to break out of its sandbox.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40849">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-34387 – Fleet is open source device management software. Prior to 4.81.1, a command inje...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34387</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34387</guid>
    <pubDate>Fri, 27 Mar 2026 19:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34387</strong></p>
  <p>Fleet is open source device management software. Prior to 4.81.1, a command injection vulnerability in Fleet's software installer pipeline allows an attacker to achieve arbitrary code execution as root (macOS/Linux) or SYSTEM (Windows) on managed hosts when an uninstall is triggered for a crafted software package. Version 4.81.1 patches the issue.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34387">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33632 – ClearanceKit intercepts file-system access events on macOS and enforces per-proc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33632</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33632</guid>
    <pubDate>Thu, 26 Mar 2026 20:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33632</strong></p>
  <p>ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 4.2.4, two file operation event types — ES_EVENT_TYPE_AUTH_EXCHANGEDATA and ES_EVENT_TYPE_AUTH_CLONE — were not intercepted by ClearanceKit's opfilter system extension, allowing local processes to bypass file access policies. Commit 6181c4a patches the vulnerability by subscribing…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33632">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33631 – ClearanceKit intercepts file-system access events on macOS and enforces per-proc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33631</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33631</guid>
    <pubDate>Thu, 26 Mar 2026 20:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33631</strong></p>
  <p>ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. In versions on the 4.1 branch and earlier, the opfilter Endpoint Security system extension enforced file access policy exclusively by intercepting ES_EVENT_TYPE_AUTH_OPEN events. Seven additional file operation event types were not intercepted, allowing any locally running process to bypass the co…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33631">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30976 – Sonarr is a PVR for Usenet and BitTorrent users. In versions on the 4.x branch p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30976</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30976</guid>
    <pubDate>Wed, 25 Mar 2026 21:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30976</strong></p>
  <p>Sonarr is a PVR for Usenet and BitTorrent users. In versions on the 4.x branch prior to 4.0.17.2950, an unauthenticated remote attacker can potentially read any file readable by the Sonarr process. These include application configuration files (containing API keys and database credentials), Windows system files, and any user-accessible files on the same drive This issue only impacts Windows syste…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30976">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28894 – A denial-of-service issue was addressed with improved input validation. This iss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28894</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28894</guid>
    <pubDate>Wed, 25 Mar 2026 01:17:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28894</strong></p>
  <p>A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. A remote attacker may be able to cause a denial-of-service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28894">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28891 – A race condition was addressed with additional validation. This issue is fixed i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28891</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28891</guid>
    <pubDate>Wed, 25 Mar 2026 01:17:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28891</strong></p>
  <p>A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to break out of its sandbox.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28891">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28876 – A parsing issue in the handling of directory paths was addressed with improved p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28876</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28876</guid>
    <pubDate>Wed, 25 Mar 2026 01:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28876</strong></p>
  <p>A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4. An app may be able to access sensitive user data.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28876">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28865 – An authentication issue was addressed with improved state management. This issue...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28865</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28865</guid>
    <pubDate>Wed, 25 Mar 2026 01:17:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28865</strong></p>
  <p>An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An attacker in a privileged network position may be able to intercept network traffic.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28865">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28855 – A permissions issue was addressed with additional restrictions. This issue is fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28855</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28855</guid>
    <pubDate>Wed, 25 Mar 2026 01:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28855</strong></p>
  <p>A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3. An app may be able to access protected user data.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28855">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28842 – The issue was addressed with improved bounds checks. This issue is fixed in macO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28842</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28842</guid>
    <pubDate>Wed, 25 Mar 2026 01:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28842</strong></p>
  <p>The issue was addressed with improved bounds checks. This issue is fixed in macOS Tahoe 26.4. A buffer overflow may result in memory corruption and unexpected app termination.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28842">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28837 – A logic issue was addressed with improved checks. This issue is fixed in macOS T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28837</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28837</guid>
    <pubDate>Wed, 25 Mar 2026 01:17:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28837</strong></p>
  <p>A logic issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28837">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28832 – An out-of-bounds read was addressed with improved bounds checking. This issue is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28832</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28832</guid>
    <pubDate>Wed, 25 Mar 2026 01:17:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28832</strong></p>
  <p>An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to disclose kernel memory.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28832">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-28827 – A parsing issue in the handling of directory paths was addressed with improved p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28827</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28827</guid>
    <pubDate>Wed, 25 Mar 2026 01:17:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-28827</strong></p>
  <p>A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to break out of its sandbox.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28827">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28825 – An out-of-bounds write issue was addressed with improved bounds checking. This i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28825</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28825</guid>
    <pubDate>Wed, 25 Mar 2026 01:17:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28825</strong></p>
  <p>An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to modify protected parts of the file system.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28825">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28821 – A validation issue existed in the entitlement verification. This issue was addre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28821</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28821</guid>
    <pubDate>Wed, 25 Mar 2026 01:17:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28821</strong></p>
  <p>A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to gain elevated privileges.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28821">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28817 – A race condition was addressed with improved state handling. This issue is fixed...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28817</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28817</guid>
    <pubDate>Wed, 25 Mar 2026 01:17:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28817</strong></p>
  <p>A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. A sandboxed process may be able to circumvent sandbox restrictions.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28817">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20701 – An access issue was addressed with additional sandbox restrictions. This issue i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20701</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20701</guid>
    <pubDate>Wed, 25 Mar 2026 01:17:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20701</strong></p>
  <p>An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to connect to a network share without user consent.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20701">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20698 – The issue was addressed with improved memory handling. This issue is fixed in iO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20698</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20698</guid>
    <pubDate>Wed, 25 Mar 2026 01:17:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20698</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to cause unexpected system termination or corrupt kernel memory.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20698">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-20688 – A path handling issue was addressed with improved validation. This issue is fixe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20688</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20688</guid>
    <pubDate>Wed, 25 Mar 2026 01:17:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-20688</strong></p>
  <p>A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4. An app may be able to break out of its sandbox.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20688">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
