Apple Patches Everything, (Mon, May 11th)
2026-05-12T01:23:52Z•544159e61ff1d7db5b26f6745a7821a2aee523544332a10a4ec5d1d2ac29a8ca
CVE-2026-31431advisoryapplecaptchacleartext-passwordscloudflare-turnstilecopy-faildirty-fragiosipadOSkernellinuxlocal-privilege-escalationmacOSmicrosoft-edgepatchessans-isctvOSvisionOSvulnerability-managementwatchOSyara-x
What happened
SANS ISC diary roundup (May 6–11, 2026): Apple released a large multi‑OS update fixing 84 vulnerabilities across iOS/iPadOS (including 26-series and older 18-series), macOS (versions 14 and 15), tvOS, watchOS and visionOS. A new Linux kernel local privilege escalation dubbed “Dirty Frag” was disclosed (researcher Hyunwoo Kim), discussed alongside the recently disclosed Copy Fail issue (CVE-2026-31431); the diary covers impacts, mitigations and recommended actions. Other entries note Cleartext password exposure in Microsoft Edge, the YARA-X 1.16.0 release, the author’s deployment of Cloudflare/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 544159e61ff1d7db5b26f6745a7821a2aee523544332a10a4ec5d1d2ac29a8ca
- Enrichment time
- 2026-05-12T01:23:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.