<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Apple macOS</title>
  <link>https://cvedaily.com/pages/tags/macos.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/macos.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Apple macOS</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:40 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-6892 – Improper handling of symbolic links in the installer of CUPS Printer Driver for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6892</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6892</guid>
    <pubDate>Fri, 29 May 2026 00:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6892</strong></p>
  <p>Improper handling of symbolic links in the installer of CUPS Printer Driver for macOS(*) may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installation to modify permissions of directories for which they would not normally have authorization.   *:Canon PIXUS iX6800 Series CUPS Printer Driver for macOS Version 16.91.0.0 or earlier (Japan)  Canon P…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6892">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6891 – Improper handling of symbolic links in the installer of My Image Garden for macO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6891</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6891</guid>
    <pubDate>Fri, 29 May 2026 00:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6891</strong></p>
  <p>Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installation to modify permissions of files for which they would not normally have authorization.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6891">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49237 – An issue was discovered in Canonical Multipass for macOS before version 1.16.3 d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49237</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49237</guid>
    <pubDate>Thu, 28 May 2026 14:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49237</strong></p>
  <p>An issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-5199. While the patch in version 1.16.0 updated the ownership of the multipassd daemon binary to root:wheel, five co-located binaries (multipass, qemu-img, qemu-system-aarch64, qemu-system-x86_64, and sshfs_server) in /Library/Application Support/com.canonical.multipass/bin/ retain…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49237">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-46307 – A logic issue was addressed with improved restrictions. This issue is fixed in m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46307</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46307</guid>
    <pubDate>Tue, 26 May 2026 22:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-46307</strong></p>
  <p>A logic issue was addressed with improved restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to access sensitive user data.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46307">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46284 – A race condition was addressed with additional validation. This issue is fixed i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46284</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46284</guid>
    <pubDate>Tue, 26 May 2026 22:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46284</strong></p>
  <p>A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An app may be able to gain root privileges.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46284">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-46280 – An out-of-bounds read was addressed with improved bounds checking. This issue is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46280</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46280</guid>
    <pubDate>Tue, 26 May 2026 22:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-46280</strong></p>
  <p>An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Tahoe 26. An app may be able to cause unexpected system termination.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46280">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-43451 – A permissions issue was addressed by removing the vulnerable code. This issue is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43451</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43451</guid>
    <pubDate>Tue, 26 May 2026 22:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-43451</strong></p>
  <p>A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26. An app may be able to access sensitive user data.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43451">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-43306 – A logic issue was addressed with improved checks. This issue is fixed in macOS S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43306</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43306</guid>
    <pubDate>Tue, 26 May 2026 22:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-43306</strong></p>
  <p>A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A malicious app may be able to gain root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43306">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-43290 – A permissions issue was addressed with additional restrictions. This issue is fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43290</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43290</guid>
    <pubDate>Tue, 26 May 2026 22:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-43290</strong></p>
  <p>A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to modify protected parts of the file system.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43290">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-43289 – A logic issue was addressed with improved validation. This issue is fixed in mac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43289</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43289</guid>
    <pubDate>Tue, 26 May 2026 22:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-43289</strong></p>
  <p>A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A malicious app may be able to access sensitive user data.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43289">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9560 – Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9560</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9560</guid>
    <pubDate>Tue, 26 May 2026 18:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9560</strong></p>
  <p>Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9560">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-46430 – Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46430</guid>
    <pubDate>Tue, 26 May 2026 17:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-46430</strong></p>
  <p>Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server bound to 0.0.0.0:5553 on Linux/macOS by default because the platform-dependent host default in engine/flags.go:39-46 set host = "" for non-Windows, and utils.JoinHostPort("", ":5553") resolves to ":5553". This vulnerability is fixed in 1.17.7.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5843 – The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM librar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5843</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5843</guid>
    <pubDate>Fri, 22 May 2026 20:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5843</strong></p>
  <p>The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configuration field in config.json. When a model's config.json specifies a model_file pointing to a Python file, MLX-LM uses importlib to load and execute it with no trust_remote_code gate or equivalent safet…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-829</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5843">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5817 – The vllm-metal inference backend in Docker Model Runner on macOS unconditionally...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5817</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5817</guid>
    <pubDate>Fri, 22 May 2026 20:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5817</strong></p>
  <p>The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This causes transformers.AutoTokenizer.from_pretrained() to import and execute arbitrary Python files included in any model pulled from an OCI registry, resulting in arbitrary code execution on the Docker host as the Docker Deskto…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-829</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5817">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47114 – IINA before 1.4.3 contains a user-assisted command execution vulnerability that ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47114</guid>
    <pubDate>Thu, 21 May 2026 20:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47114</strong></p>
  <p>IINA before 1.4.3 contains a user-assisted command execution vulnerability that allows remote attackers to execute arbitrary commands by supplying malicious mpv_-prefixed query parameters through the iina://open custom URL scheme handler. Attackers can deliver a crafted URL via a browser that passes unvalidated mpv_options/input-commands parameters into the mpv runtime, causing arbitrary command…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39309 – Trilium Notes is a cross-platform, hierarchical note taking application focused ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39309</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39309</guid>
    <pubDate>Wed, 20 May 2026 00:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39309</strong></p>
  <p>Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Electron configuration is vulnerable to TCC Bypass via Prompt Spoofing, allowing local attackers to trigger misleading macOS permission prompts by running malicious code under the identity of the trusted app. The root cause is that the RunA…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39309">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32323 – Mullvad VPN is a VPN client app for desktop and mobile. When using macOS with ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32323</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32323</guid>
    <pubDate>Tue, 19 May 2026 02:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32323</strong></p>
  <p>Mullvad VPN is a VPN client app for desktop and mobile. When using macOS with versions 2026.1 and below, Mullvad VPN may allow local privilege escalation during installation or upgrade. The installer package executes binaries from /Applications/Mullvad VPN.app without verifying if the bundle is attacker-controlled or that the path is the legitimate Mullvad application. A user in the admin group c…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32323">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-26191 – Fleet is open source device management software. Prior to version 4.81.0, a vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26191</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26191</guid>
    <pubDate>Thu, 14 May 2026 20:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-26191</strong></p>
  <p>Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet's software installer pipeline could allow a crafted software package to execute arbitrary commands as root (macOS/Linux) or SYSTEM (Windows) on managed endpoints when an uninstall is triggered. When a software package (.pkg, .deb, .rpm, .exe, or .msi) is uploaded to Fleet, metadata is extracted from…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26191">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0251 – Multiple local privilege escalation vulnerabilities in the Palo Alto Networks Gl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0251</guid>
    <pubDate>Wed, 13 May 2026 19:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0251</strong></p>
  <p>Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges.  The GlobalProtect app on iOS, Android, Chrome OS and GlobalProtect UWP app are not affect…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0248 – An improper certificate validation vulnerability in the Prisma Access Agent® for...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0248</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0248</guid>
    <pubDate>Wed, 13 May 2026 19:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0248</strong></p>
  <p>An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. By presenting a certificate for any domain issued by a trusted Certificate Authority, the attacker can capture sensitive device information.    The Prisma Access Agent on macOS, Windows, Linux and iOS are…</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0248">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0246 – A vulnerability with a privilege management mechanism in the Palo Alto Networks ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0246</guid>
    <pubDate>Wed, 13 May 2026 19:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0246</strong></p>
  <p>A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally authenticated non-administrative user to escalate their privileges to root on macOS and Linux or NT AUTHORITY\SYSTEM on Windows. This allows the user to execute arbitrary code and read sensitive information otherwise accessible only to privileged accounts.    The Prisma Access Ag…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0236 – A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0236</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0236</guid>
    <pubDate>Wed, 13 May 2026 19:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0236</strong></p>
  <p>A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its AppleScript interface allowing a locally authenticated non-admin user to leverage this exposed Apple Event handler to send unauthorized commands to the browser.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0236">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0237 – An improper protection of alternate path vulnerability in Palo Alto Networks Pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0237</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0237</guid>
    <pubDate>Wed, 13 May 2026 18:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0237</strong></p>
  <p>An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allows a locally authenticated non-admin user to leverage an exposed communication channel to send unauthorized commands to the browser, bypassing security controls.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-424</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0237">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-43524 – An access issue was addressed with additional sandbox restrictions. This issue i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43524</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43524</guid>
    <pubDate>Tue, 12 May 2026 18:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-43524</strong></p>
  <p>An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.2. An app may be able to break out of its sandbox.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43524">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43668 – A use after free issue was addressed with improved memory management. This issue...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43668</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43668</guid>
    <pubDate>Mon, 11 May 2026 21:19:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43668</strong></p>
  <p>A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43668">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-43666 – An out-of-bounds write issue was addressed with improved bounds checking. This i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43666</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43666</guid>
    <pubDate>Mon, 11 May 2026 21:19:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-43666</strong></p>
  <p>An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An attacker on the local network may be able to cause a denial-of-service.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43666">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43661 – A buffer overflow issue was addressed with improved memory handling. This issue ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43661</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43661</guid>
    <pubDate>Mon, 11 May 2026 21:19:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43661</strong></p>
  <p>A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. Processing a maliciously crafted image may corrupt process memory.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43661">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43660 – A validation issue was addressed with improved logic. This issue is fixed in Saf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43660</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43660</guid>
    <pubDate>Mon, 11 May 2026 21:19:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43660</strong></p>
  <p>A validation issue was addressed with improved logic. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43660">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-43659 – A race condition was addressed with additional validation. This issue is fixed i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43659</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43659</guid>
    <pubDate>Mon, 11 May 2026 21:19:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-43659</strong></p>
  <p>A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, visionOS 26.5. An app may be able to access sensitive user data.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43659">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43658 – The issue was addressed with improved memory handling. This issue is fixed in Sa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43658</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43658</guid>
    <pubDate>Mon, 11 May 2026 21:19:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43658</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43658">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43656 – An out-of-bounds write issue was addressed with improved input validation. This ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43656</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43656</guid>
    <pubDate>Mon, 11 May 2026 21:19:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43656</strong></p>
  <p>An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. Parsing a maliciously crafted file may lead to an unexpected app termination.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43656">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43655 – An out-of-bounds read was addressed with improved bounds checking. This issue is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43655</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43655</guid>
    <pubDate>Mon, 11 May 2026 21:19:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43655</strong></p>
  <p>An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination or read kernel memory.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43655">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43654 – The issue was addressed with improved memory handling. This issue is fixed in iO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43654</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43654</guid>
    <pubDate>Mon, 11 May 2026 21:19:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43654</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to disclose kernel memory.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-497</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43654">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-43653 – The issue was addressed with improved memory handling. This issue is fixed in iO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43653</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43653</guid>
    <pubDate>Mon, 11 May 2026 21:19:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-43653</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5. An attacker on the local network may be able to cause a denial-of-service.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43653">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43652 – A permissions issue was addressed with additional restrictions. This issue is fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43652</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43652</guid>
    <pubDate>Mon, 11 May 2026 21:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43652</strong></p>
  <p>A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.5. An app may be able to access protected user data.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43652">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39871 – A path handling issue was addressed with improved logic. This issue is fixed in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39871</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39871</guid>
    <pubDate>Mon, 11 May 2026 21:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39871</strong></p>
  <p>A path handling issue was addressed with improved logic. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to observe unprotected user data.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-552</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39871">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39870 – The issue was addressed with improved memory handling. This issue is fixed in ma...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39870</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39870</guid>
    <pubDate>Mon, 11 May 2026 21:18:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39870</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. Processing a maliciously crafted image may corrupt process memory.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39870">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39869 – The issue was addressed with improved memory handling. This issue is fixed in iO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39869</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39869</guid>
    <pubDate>Mon, 11 May 2026 21:18:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39869</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing an audio stream in a maliciously crafted media file may terminate the process.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39869">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28996 – A race condition was addressed with additional validation. This issue is fixed i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28996</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28996</guid>
    <pubDate>Mon, 11 May 2026 21:18:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28996</strong></p>
  <p>A race condition was addressed with additional validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to access sensitive user data.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28996">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28995 – A logic issue was addressed with improved restrictions. This issue is fixed in i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28995</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28995</guid>
    <pubDate>Mon, 11 May 2026 21:18:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28995</strong></p>
  <p>A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A malicious app may be able to break out of its sandbox.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28995">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28994 – A use after free issue was addressed with improved memory management. This issue...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28994</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28994</guid>
    <pubDate>Mon, 11 May 2026 21:18:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28994</strong></p>
  <p>A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An attacker in a privileged network position may be able to perform denial-of-service attack using crafted Wi-Fi packets.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28994">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28993 – This issue was addressed by adding an additional prompt for user consent. This i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28993</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28993</guid>
    <pubDate>Mon, 11 May 2026 21:18:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28993</strong></p>
  <p>This issue was addressed by adding an additional prompt for user consent. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, visionOS 26.5. An app may be able to access user-sensitive data.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28993">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28992 – A memory corruption vulnerability was addressed with improved locking. This issu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28992</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28992</guid>
    <pubDate>Mon, 11 May 2026 21:18:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28992</strong></p>
  <p>A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An attacker may be able to cause unexpected app termination.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28992">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28991 – An out-of-bounds read was addressed with improved bounds checking. This issue is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28991</guid>
    <pubDate>Mon, 11 May 2026 21:18:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28991</strong></p>
  <p>An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause a denial-of-service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28990 – The issue was addressed with improved memory handling. This issue is fixed in iO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28990</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28990</guid>
    <pubDate>Mon, 11 May 2026 21:18:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28990</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing a maliciously crafted image may corrupt process memory.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28990">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28988 – A permissions issue was addressed with additional restrictions. This issue is fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28988</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28988</guid>
    <pubDate>Mon, 11 May 2026 21:18:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28988</strong></p>
  <p>A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5, watchOS 26.5. An app may be able to bypass certain Privacy preferences.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28988">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28987 – A logging issue was addressed with improved data redaction. This issue is fixed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28987</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28987</guid>
    <pubDate>Mon, 11 May 2026 21:18:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28987</strong></p>
  <p>A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to leak sensitive kernel state.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28987">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28986 – A race condition was addressed with additional validation. This issue is fixed i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28986</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28986</guid>
    <pubDate>Mon, 11 May 2026 21:18:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28986</strong></p>
  <p>A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28986">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28985 – A null pointer dereference was addressed with improved input validation. This is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28985</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28985</guid>
    <pubDate>Mon, 11 May 2026 21:18:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28985</strong></p>
  <p>A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5. An attacker on the local network may be able to cause a denial-of-service.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28985">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28983 – A type confusion issue was addressed with improved checks. This issue is fixed i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28983</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28983</guid>
    <pubDate>Mon, 11 May 2026 21:18:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28983</strong></p>
  <p>A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A remote attacker may be able to cause a denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-843</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28983">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28978 – A permissions issue was addressed with additional restrictions. This issue is fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28978</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28978</guid>
    <pubDate>Mon, 11 May 2026 21:18:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28978</strong></p>
  <p>A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A malicious app may be able to break out of its sandbox.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28978">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28977 – The issue was addressed with improved bounds checks. This issue is fixed in iOS ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28977</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28977</guid>
    <pubDate>Mon, 11 May 2026 21:18:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28977</strong></p>
  <p>The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing a maliciously crafted file may lead to unexpected app termination.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28977">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28976 – An information leakage was addressed with additional validation. This issue is f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28976</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28976</guid>
    <pubDate>Mon, 11 May 2026 21:18:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28976</strong></p>
  <p>An information leakage was addressed with additional validation. This issue is fixed in macOS Tahoe 26.5. An app may be able to gain root privileges.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28976">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28974 – This issue was addressed with improved checks to prevent unauthorized actions. T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28974</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28974</guid>
    <pubDate>Mon, 11 May 2026 21:18:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28974</strong></p>
  <p>This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause a denial-of-service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28974">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28972 – An out-of-bounds write issue was addressed with improved input validation. This ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28972</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28972</guid>
    <pubDate>Mon, 11 May 2026 21:18:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28972</strong></p>
  <p>An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination or write kernel memory.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28972">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28971 – The issue was addressed with improved UI handling. This issue is fixed in Safari...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28971</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28971</guid>
    <pubDate>Mon, 11 May 2026 21:18:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28971</strong></p>
  <p>The issue was addressed with improved UI handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. A malicious iframe may use another website’s download settings.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28971">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28969 – A use after free issue was addressed with improved memory management. This issue...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28969</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28969</guid>
    <pubDate>Mon, 11 May 2026 21:18:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28969</strong></p>
  <p>A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28969">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28962 – This issue was addressed with improved access restrictions. This issue is fixed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28962</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28962</guid>
    <pubDate>Mon, 11 May 2026 21:18:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28962</strong></p>
  <p>This issue was addressed with improved access restrictions. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. Processing maliciously crafted web content may disclose sensitive user information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28962">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28961 – This issue was addressed with improved checks. This issue is fixed in macOS Taho...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28961</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28961</guid>
    <pubDate>Mon, 11 May 2026 21:18:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28961</strong></p>
  <p>This issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.5. An attacker with physical access to a locked device may be able to view sensitive user information.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28961">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28959 – A buffer overflow was addressed with improved bounds checking. This issue is fix...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28959</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28959</guid>
    <pubDate>Mon, 11 May 2026 21:18:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28959</strong></p>
  <p>A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28959">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28958 – This issue was addressed with improved data protection. This issue is fixed in S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28958</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28958</guid>
    <pubDate>Mon, 11 May 2026 21:18:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28958</strong></p>
  <p>This issue was addressed with improved data protection. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. An app may be able to access sensitive user data.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28958">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28956 – A memory corruption issue was addressed with improved input validation. This iss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28956</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28956</guid>
    <pubDate>Mon, 11 May 2026 21:18:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28956</strong></p>
  <p>A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28956">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28955 – The issue was addressed with improved memory handling. This issue is fixed in Sa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28955</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28955</guid>
    <pubDate>Mon, 11 May 2026 21:18:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28955</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28955">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28954 – A file quarantine bypass was addressed with additional checks. This issue is fix...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28954</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28954</guid>
    <pubDate>Mon, 11 May 2026 21:18:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28954</strong></p>
  <p>A file quarantine bypass was addressed with additional checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A maliciously crafted disk image may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28954">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28953 – The issue was addressed with improved memory handling. This issue is fixed in Sa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28953</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28953</guid>
    <pubDate>Mon, 11 May 2026 21:18:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28953</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28953">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28952 – An integer overflow was addressed with improved input validation. This issue is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28952</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28952</guid>
    <pubDate>Mon, 11 May 2026 21:18:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28952</strong></p>
  <p>An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to cause unexpected system termination.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28952">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28951 – An authorization issue was addressed with improved state management. This issue ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28951</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28951</guid>
    <pubDate>Mon, 11 May 2026 21:18:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28951</strong></p>
  <p>An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to gain root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28951">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28947 – A use-after-free issue was addressed with improved memory management. This issue...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28947</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28947</guid>
    <pubDate>Mon, 11 May 2026 21:18:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28947</strong></p>
  <p>A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28947">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28946 – A use-after-free issue was addressed with improved memory management. This issue...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28946</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28946</guid>
    <pubDate>Mon, 11 May 2026 21:18:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28946</strong></p>
  <p>A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28946">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28944 – The issue was addressed with improved memory handling. This issue is fixed in Sa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28944</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28944</guid>
    <pubDate>Mon, 11 May 2026 21:18:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28944</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28944">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28943 – A logging issue was addressed with improved data redaction. This issue is fixed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28943</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28943</guid>
    <pubDate>Mon, 11 May 2026 21:18:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28943</strong></p>
  <p>A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to determine kernel memory layout.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28943">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28942 – A use-after-free issue was addressed with improved memory management. This issue...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28942</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28942</guid>
    <pubDate>Mon, 11 May 2026 21:18:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28942</strong></p>
  <p>A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28942">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28941 – The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28941</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28941</guid>
    <pubDate>Mon, 11 May 2026 21:18:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28941</strong></p>
  <p>The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Tahoe 26.5. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28941">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28940 – The issue was addressed with improved memory handling. This issue is fixed in iO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28940</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28940</guid>
    <pubDate>Mon, 11 May 2026 21:18:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28940</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5. Processing a maliciously crafted image may corrupt process memory.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28940">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28936 – The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28936</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28936</guid>
    <pubDate>Mon, 11 May 2026 21:18:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28936</strong></p>
  <p>The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sonoma 14.8.7, macOS Tahoe 26.5, visionOS 26.5. Processing a maliciously crafted file may lead to unexpected app termination.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28936">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28930 – A permissions issue was addressed with additional restrictions. This issue is fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28930</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28930</guid>
    <pubDate>Mon, 11 May 2026 21:18:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28930</strong></p>
  <p>A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.5. An app may be able to access protected user data.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28930">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28929 – A logic issue was addressed with improved checks. This issue is fixed in iOS 18...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28929</guid>
    <pubDate>Mon, 11 May 2026 21:18:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28929</strong></p>
  <p>A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. Replying to an email could display remote images in Mail in Lockdown Mode.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1254</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28925 – A buffer overflow was addressed with improved bounds checking. This issue is fix...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28925</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28925</guid>
    <pubDate>Mon, 11 May 2026 21:18:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28925</strong></p>
  <p>A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to cause unexpected system termination or write kernel memory.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28925">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28924 – A race condition was addressed with improved handling of symbolic links. This is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28924</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28924</guid>
    <pubDate>Mon, 11 May 2026 21:18:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28924</strong></p>
  <p>A race condition was addressed with improved handling of symbolic links. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to access Contacts without user consent.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28924">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28923 – A logging issue was addressed with improved data redaction. This issue is fixed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28923</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28923</guid>
    <pubDate>Mon, 11 May 2026 21:18:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28923</strong></p>
  <p>A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A malicious app may be able to break out of its sandbox.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28923">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28922 – This issue was addressed through improved state management. This issue is fixed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28922</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28922</guid>
    <pubDate>Mon, 11 May 2026 21:18:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28922</strong></p>
  <p>This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to access private information.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28922">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28920 – An information leakage was addressed with additional validation. This issue is f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28920</guid>
    <pubDate>Mon, 11 May 2026 21:18:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28920</strong></p>
  <p>An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Visiting a maliciously crafted website may leak sensitive data.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28919 – A consistency issue was addressed with improved state handling. This issue is fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28919</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28919</guid>
    <pubDate>Mon, 11 May 2026 21:18:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28919</strong></p>
  <p>A consistency issue was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to gain root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28919">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28918 – An out-of-bounds access issue was addressed with improved bounds checking. This ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28918</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28918</guid>
    <pubDate>Mon, 11 May 2026 21:18:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28918</strong></p>
  <p>An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Parsing a maliciously crafted file may lead to an unexpected app termination.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28918">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28917 – The issue was addressed with improved input validation. This issue is fixed in S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28917</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28917</guid>
    <pubDate>Mon, 11 May 2026 21:18:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28917</strong></p>
  <p>The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28917">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28915 – A parsing issue in the handling of directory paths was addressed with improved p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28915</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28915</guid>
    <pubDate>Mon, 11 May 2026 21:18:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28915</strong></p>
  <p>A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to gain root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28915">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28914 – A logic issue was addressed with improved file handling. This issue is fixed in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28914</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28914</guid>
    <pubDate>Mon, 11 May 2026 21:18:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28914</strong></p>
  <p>A logic issue was addressed with improved file handling. This issue is fixed in macOS Tahoe 26.5. A maliciously crafted ZIP archive may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-358</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28914">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28913 – The issue was addressed with improved memory handling. This issue is fixed in Sa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28913</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28913</guid>
    <pubDate>Mon, 11 May 2026 21:18:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28913</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28913">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-28910 – This issue was addressed with improved permissions checking. This issue is fixed...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28910</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28910</guid>
    <pubDate>Mon, 11 May 2026 21:18:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-28910</strong></p>
  <p>This issue was addressed with improved permissions checking. This issue is fixed in macOS Tahoe 26.4. A malicious app may be able to access arbitrary files.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28910">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28908 – A denial of service issue was addressed by removing the vulnerable code. This is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28908</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28908</guid>
    <pubDate>Mon, 11 May 2026 21:18:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28908</strong></p>
  <p>A denial of service issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to modify protected parts of the file system.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28908">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28907 – The issue was addressed with improved input validation. This issue is fixed in S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28907</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28907</guid>
    <pubDate>Mon, 11 May 2026 21:18:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28907</strong></p>
  <p>The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28907">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28906 – This issue was addressed through improved state management. This issue is fixed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28906</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28906</guid>
    <pubDate>Mon, 11 May 2026 21:18:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28906</strong></p>
  <p>This issue was addressed through improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, visionOS 26.5. An attacker may be able to track users through their IP address.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-359</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28906">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28905 – The issue was addressed with improved memory handling. This issue is fixed in Sa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28905</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28905</guid>
    <pubDate>Mon, 11 May 2026 21:18:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28905</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28905">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28904 – The issue was addressed with improved memory handling. This issue is fixed in Sa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28904</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28904</guid>
    <pubDate>Mon, 11 May 2026 21:18:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28904</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28904">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28903 – The issue was addressed with improved memory handling. This issue is fixed in Sa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28903</guid>
    <pubDate>Mon, 11 May 2026 21:18:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28903</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28902 – The issue was addressed with improved memory handling. This issue is fixed in Sa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28902</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28902</guid>
    <pubDate>Mon, 11 May 2026 21:18:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28902</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28902">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28901 – The issue was addressed with improved memory handling. This issue is fixed in Sa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28901</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28901</guid>
    <pubDate>Mon, 11 May 2026 21:18:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28901</strong></p>
  <p>The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28901">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28897 – A buffer overflow was addressed with improved input validation. This issue is fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28897</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28897</guid>
    <pubDate>Mon, 11 May 2026 21:18:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28897</strong></p>
  <p>A buffer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A local user may be able to cause unexpected system termination or read kernel memory.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28897">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28883 – A use-after-free issue was addressed with improved memory management. This issue...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28883</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28883</guid>
    <pubDate>Mon, 11 May 2026 21:18:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28883</strong></p>
  <p>A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28883">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28860 – The issue was addressed with improved input validation. This issue is fixed in i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28860</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28860</guid>
    <pubDate>Mon, 11 May 2026 21:18:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28860</strong></p>
  <p>The issue was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. A local attacker may be able to modify the state of the Keychain.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28860">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
