Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-28913

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
iOS and iPadOS, macOS, watchOS, tvOS, Safari
Provider severity
HIGH
Conflicts
2

CVE-2026-28912

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A user may be able to elevate privileges.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
HIGH
Conflicts
1

CVE-2026-28911

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to corrupt memory of a system process.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
CRITICAL
Conflicts
1

CVE-2026-28910

This issue was addressed with improved permissions checking. This issue is fixed in macOS Tahoe 26.4. A malicious app may be able to access arbitrary files.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
LOW
Conflicts
1

CVE-2026-2891

The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP server and receive malformed data. HP is releasing updates to mitigate these potential vulnerabilities.

PUBLISHED
Vendor
HP Inc, HP Inc, HP Inc
Product
Trio C60, Edge E, CCX
Provider severity
HIGH
Conflicts
1

CVE-2026-28909

Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext. This issue is fixed in container version 0.12.3.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-28908

A denial of service issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to modify protected parts of the file system.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
HIGH
Conflicts
1

CVE-2026-28907

The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple, Apple
Product
tvOS, iOS and iPadOS, Safari, visionOS, watchOS, macOS
Provider severity
HIGH
Conflicts
2

CVE-2026-28906

This issue was addressed through improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, visionOS 26.5. An attacker may be able to track users through their IP address.

PUBLISHED
Vendor
Apple, Apple, Apple
Product
visionOS, iOS and iPadOS, macOS
Provider severity
HIGH
Conflicts
2

CVE-2026-28905

A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper memory handling.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Apple, Red Hat, Red Hat, Red Hat, Red Hat, Apple, Red Hat, Red Hat, Apple, Red Hat, Red Hat, Red Hat, Red Hat, Apple, Apple, Red Hat
Product
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 6, iOS and iPadOS, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, tvOS, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On, macOS, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Safari, visionOS, Red Hat Enterprise Linux 7
Provider severity
HIGH
Conflicts
3

CVE-2026-28904

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.

PUBLISHED
Vendor
Red Hat, Apple, Red Hat, Red Hat, Red Hat, Red Hat, Apple, Apple, Red Hat, Red Hat, Red Hat, Red Hat, Apple, Red Hat, Red Hat, Red Hat, Red Hat, Apple, Apple, Red Hat
Product
Red Hat Enterprise Linux 9.6 Extended Update Support, Safari, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 7, tvOS, visionOS, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 9, iOS and iPadOS, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, macOS, watchOS, Red Hat Enterprise Linux 8.8 Telecommunications Update Service
Provider severity
HIGH
Conflicts
3

CVE-2026-28903

A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper memory handling.

PUBLISHED
Vendor
Red Hat, Apple, Red Hat, Red Hat, Apple, Red Hat, Red Hat, Apple, Red Hat, Red Hat, Red Hat, Red Hat, Apple, Apple, Apple, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, iOS and iPadOS, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Safari, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat Enterprise Linux 8, macOS, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, visionOS, watchOS, tvOS, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-28902

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.

PUBLISHED
Vendor
Apple, Red Hat, Red Hat, Red Hat, Red Hat, Apple, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Apple, Apple, Red Hat, Red Hat, Red Hat, Apple, Red Hat, Apple, Red Hat
Product
macOS, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 6, iOS and iPadOS, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, visionOS, Safari, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 7 Extended Lifecycle Support, tvOS, Red Hat Enterprise Linux 9.6 Extended Update Support, watchOS, Red Hat Enterprise Linux 9
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-28901

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.

PUBLISHED
Vendor
Red Hat, Red Hat, Apple, Red Hat, Apple, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Apple, Red Hat, Apple, Red Hat, Red Hat, Apple, Apple, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Safari, Red Hat Enterprise Linux 7, macOS, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, iOS and iPadOS, Red Hat Enterprise Linux 9, visionOS, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On, tvOS, watchOS, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 7 Extended Lifecycle Support
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-28900

A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A maliciously crafted ZIP archive may bypass Gatekeeper checks.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-2890

The Formidable Forms plugin for WordPress is vulnerable to a payment integrity bypass in all versions up to, and including, 6.28. This is due to the Stripe Link return handler (`handle_one_time_stripe_link_return_url`) marking payment records as complete based solely on the Stripe PaymentIntent status without comparing the intent's charged amount against the expected payment amount, and the `verify_intent()` function validating only client secret ownership without binding intents to specific for

PUBLISHED
Vendor
strategy11team
Product
Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder
Provider severity
HIGH
Conflicts
0

CVE-2026-28898

swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header values for control characters before placing them into the translated HTTP/1.1 message. swift-nio-http2 1.44.1 adds validation of all pseudo-header values (:path, :authority, :scheme, :method, and :status) at both the HPACK header validation layer and the HTTP/2-to-HTTP/1.1 translation layer. Requests or responses containing CR, LF, or NUL bytes in any pseudo-header value are now rejected with a connection error. This issu

PUBLISHED
Vendor
Apple
Product
swift-nio-http2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-28897

A buffer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A local user may be able to cause unexpected system termination or read kernel memory.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
tvOS, visionOS, watchOS, macOS, iOS and iPadOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-28896

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An attacker may be able to cause unexpected system termination or read kernel memory.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
HIGH
Conflicts
1

CVE-2026-28895

The issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4. An attacker with physical access to an iOS device with Stolen Device Protection enabled may be able to access biometrics-gated Protected Apps with the passcode.

PUBLISHED
Vendor
Apple
Product
iOS and iPadOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-28894

A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. A remote attacker may be able to cause a denial-of-service.

PUBLISHED
Vendor
Apple, Apple
Product
iOS and iPadOS, macOS
Provider severity
HIGH
Conflicts
2

CVE-2026-28893

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Tahoe 26.4. A document may be written to a temporary file when using print preview.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
LOW
Conflicts
1

CVE-2026-28892

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to modify protected parts of the file system.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-28891

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to break out of its sandbox.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
HIGH
Conflicts
1

CVE-2026-28890

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 26.4. An app may be able to cause unexpected system termination.

PUBLISHED
Vendor
Apple
Product
Xcode
Provider severity
MEDIUM
Conflicts
1

CVE-2026-2889

A vulnerability was detected in CCExtractor up to 0.96.5. Affected is the function processmp4 in the library src/lib_ccx/mp4.c. Performing a manipulation results in use after free. The attack is only possible with local access. The exploit is now public and may be used. Upgrading to version 0.96.6 is able to address this issue. The patch is named fd7271bae238ccb3ae8a71304ea64f0886324925. You should upgrade the affected component.

PUBLISHED
Vendor
n/a
Product
CCExtractor
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-28889

A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 26.4. An app may be able to read arbitrary files as root.

PUBLISHED
Vendor
Apple
Product
Xcode
Provider severity
MEDIUM
Conflicts
1

CVE-2026-28888

A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to gain root privileges.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-28886

A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. A user in a privileged network position may be able to cause a denial-of-service.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
tvOS, macOS, iOS and iPadOS, visionOS, watchOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-28883

A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory management and result in an unexpected process crash.

PUBLISHED
Vendor
Red Hat, Red Hat, Apple, Apple, Red Hat, Red Hat, Red Hat, Apple, Red Hat, Apple, Red Hat, Apple, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Apple, Red Hat
Product
Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, tvOS, macOS, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On, watchOS, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Safari, Red Hat Enterprise Linux 9, visionOS, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 8, iOS and iPadOS, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Provider severity
HIGH
Conflicts
3

CVE-2026-28882

This issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to enumerate a user's installed apps.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
iOS and iPadOS, macOS, watchOS, tvOS, visionOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-28881

A privacy issue was addressed by moving sensitive data. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-28880

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4. An app may be able to enumerate a user's installed apps.

PUBLISHED
Vendor
Apple, Apple, Apple
Product
macOS, iOS and iPadOS, visionOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-2888

The Formidable Forms plugin for WordPress is vulnerable to an authorization bypass through user-controlled key in all versions up to, and including, 6.28. This is due to the `frm_strp_amount` AJAX handler (`update_intent_ajax`) overwriting the global `$_POST` data with attacker-controlled JSON input and then using those values to recalculate payment amounts via field shortcode resolution in `generate_false_entry()`. The handler relies on a nonce that is publicly exposed in the page's JavaScript

PUBLISHED
Vendor
strategy11team
Product
Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28879

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. Processing maliciously crafted web content may lead to an unexpected process crash.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
macOS, tvOS, watchOS, iOS and iPadOS, visionOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-28878

A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.7, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to enumerate a user's installed apps.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
macOS, watchOS, visionOS, tvOS, iOS and iPadOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-28877

An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. An app may be able to access sensitive user data.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple
Product
iOS and iPadOS, watchOS, macOS, visionOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-28876

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4. An app may be able to access sensitive user data.

PUBLISHED
Vendor
Apple, Apple, Apple
Product
visionOS, iOS and iPadOS, macOS
Provider severity
HIGH
Conflicts
2

CVE-2026-28875

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote attacker may be able to cause a denial-of-service.

PUBLISHED
Vendor
Apple
Product
iOS and iPadOS
Provider severity
HIGH
Conflicts
1

CVE-2026-28874

The issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote attacker may cause an unexpected app termination.

PUBLISHED
Vendor
Apple
Product
iOS and iPadOS
Provider severity
HIGH
Conflicts
1

CVE-2026-28873

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4. An app may be able to circumvent App Privacy Report logging.

PUBLISHED
Vendor
Apple
Product
iOS and iPadOS
Provider severity
HIGH
Conflicts
1

CVE-2026-28872

A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4. A remote attacker may be able to cause a denial-of-service.

PUBLISHED
Vendor
Apple
Product
iOS and iPadOS
Provider severity
HIGH
Conflicts
1

CVE-2026-28871

A logic issue was addressed with improved checks. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4. Visiting a maliciously crafted website may lead to a cross-site scripting attack.

PUBLISHED
Vendor
Apple, Apple, Apple
Product
iOS and iPadOS, Safari, macOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-28870

An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to access sensitive user data.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
tvOS, iOS and iPadOS, watchOS, visionOS, macOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-2887

A security vulnerability has been detected in aardappel lobster up to 2025.4. This impacts the function lobster::TypeName in the library dev/src/lobster/idents.h. Such manipulation leads to uncontrolled recursion. The attack can only be performed from a local environment. The exploit has been disclosed publicly and may be used. Upgrading to version 2026.1 will fix this issue. The name of the patch is 8ba49f98ccfc9734ef352146806433a41d9f9aa6. It is advisable to upgrade the affected component.

PUBLISHED
Vendor
aardappel
Product
lobster
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-28868

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. An app may be able to disclose kernel memory.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple
Product
watchOS, iOS and iPadOS, macOS, visionOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-28867

This issue was addressed with improved authentication. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to leak sensitive kernel state.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
visionOS, tvOS, watchOS, iOS and iPadOS, macOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-28866

This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access sensitive user data.

PUBLISHED
Vendor
Apple, Apple
Product
iOS and iPadOS, macOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-28865

An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An attacker in a privileged network position may be able to intercept network traffic.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
tvOS, watchOS, iOS and iPadOS, visionOS, macOS
Provider severity
HIGH
Conflicts
2

CVE-2026-28864

This issue was addressed with improved permissions checking. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. A local attacker may gain access to user's Keychain items.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple
Product
visionOS, macOS, iOS and iPadOS, watchOS
Provider severity
LOW
Conflicts
2