Apple Patches Everything (July 2026), (Wed, Jul 29th)
Apple Patches Everything (July 2026)
I am a bit late with this summary, but this week Apple released updates to all its operating systems and Safari. The Safari update, as usual, targets macOS prior to macOS 26. macOS updates covered the two older versions (14 and 15), while other operating system patches only covered the current 26 versions.
A total of 187 vulnerabilities are addressed in this update. Many cover multiple operating systems. Apple did not label any of the vulnerabilities as already being exploited.
Three vulnerabilities that caught my interest are CVE-2026-28849, CVE-2026-28900, and CVE-2026-28914. These issues appear to be the vulnerability described in https://mysk.blog/2026/07/23/macos-overwrite-app-executables/ earlier this week. But I have not seen a confirmation that this is the same issue.
Other than that, the vulnerabilities are "more of the usual". A lot of DoS and privilege-escalation/sandbox-escape issues, and the usual WebKit issues. In June, Apple announced that it may publish occasional "security update only" releases. This release does not contain any significant new functionality but is also meant as a "prep release" for iOS/macOS 27, as it makes some adjustments to Spotlight to get the system ready for the new major OS releases coming in the fall.
| iOS 26.6 and iPadOS 26.6 | macOS Tahoe 26.6 | macOS Sequoia 15.7.8 | macOS Sonoma 14.8.8 | tvOS 26.6 | watchOS 26.6 | visionOS 26.6 | Safari 26.6 |
|---|---|---|---|---|---|---|---|
| CVE-2025-43325: An app may be able to access sensitive user data. Affects Icons |
|||||||
| x | x | ||||||
| CVE-2026-20672: An app may be able to access sensitive user data. Affects LaunchServices |
|||||||
| x | x | ||||||
| CVE-2026-23918: A remote attacker may be able to cause a denial-of-service. Affects apache |
|||||||
| x | x | x | |||||
| CVE-2026-28849: A maliciously crafted ZIP archive may bypass Gatekeeper checks. Affects BOM |
|||||||
| x | x | ||||||
| CVE-2026-28896: An attacker may be able to cause unexpected system termination or read kernel memory. Affects ppp |
|||||||
| x | x | ||||||
| CVE-2026-28900: A maliciously crafted ZIP archive may bypass Gatekeeper checks. Affects libarchive |
|||||||
| x | x | ||||||
| CVE-2026-28911: A malicious app may be able to corrupt memory of a system process. Affects Metal |
|||||||
| x | x | ||||||
| CVE-2026-28912: A user may be able to elevate privileges. Affects PackageKit |
|||||||
| x | x | ||||||
| CVE-2026-28914: A maliciously crafted ZIP archive may bypass Gatekeeper checks. Affects zip |
|||||||
| x | x | ||||||
| CVE-2026-28926: An app may be able to elevate privileges. Affects Disk Images |
|||||||
| x | x | ||||||
| CVE-2026-28928: An app may be able to cause unexpected system termination. Affects Apple Neural Engine |
|||||||
| x | x | x | x | ||||
| CVE-2026-28931: Connecting to a malicious NFS server may lead to kernel memory corruption. Affects Kernel |
|||||||
| x | x | x | x | ||||
| CVE-2026-28932: An app may be able to cause a denial of service. Affects xar |
|||||||
| x | x | x | |||||
| CVE-2026-28936: Processing a maliciously crafted file may lead to unexpected app termination. Affects CoreServices |
|||||||
| x | x | ||||||
| CVE-2026-28945: An app may be able to bypass network restrictions. Affects Disk Images |
|||||||
| x | x | x | |||||
| CVE-2026-28961: An attacker with physical access to a locked device may be able to view sensitive user information. Affects Network Extensions |
|||||||
| x | x | ||||||
| CVE-2026-28973: A malicious app may be able to break out of its sandbox. Affects libc |
|||||||
| x | x | x | x | x | |||
| CVE-2026-28981: Processing a maliciously crafted image may lead to arbitrary code execution. Affects HFS |
|||||||
| x | x | x | |||||
| CVE-2026-28982: A remote user may be able to cause unexpected system termination or corrupt kernel memory. Affects Kernel |
|||||||
| x | x | x | |||||
| CVE-2026-28983: A remote attacker may be able to cause a denial of service. Affects LaunchServices |
|||||||
| x | x | ||||||
| CVE-2026-39868: An app may be able to cause unexpected system termination or corrupt kernel memory. Affects Kernel |
|||||||
| x | x | x | x | x | |||
| CVE-2026-39873: Connecting to a malicious SMB server may lead to unexpected system termination. Affects SMB |
|||||||
| x | x | x | |||||
| CVE-2026-39874: A malicious app may be able to gain root privileges. Affects Remote Management |
|||||||
| x | x | x | |||||
| CVE-2026-39875: A malicious app may be able to gain root privileges. Affects CUPS |
|||||||
| x | x | x | |||||
| CVE-2026-39877: An app may be able to disclose kernel memory. Affects IOSkywalkFamily |
|||||||
| x | x | ||||||
| CVE-2026-43661: Processing a maliciously crafted image may corrupt process memory. Affects ImageIO |
|||||||
| x | x | ||||||
| CVE-2026-43665: A local attacker may be able to determine the legacy VNC password configured for Screen Sharing. Affects Screen Sharing Server |
|||||||
| x | x | ||||||
| CVE-2026-43672: A malicious application may be able to bypass Privacy preferences. Affects Assets |
|||||||
| x | x | x | |||||
| CVE-2026-43673: Processing a maliciously crafted audio file may corrupt process memory. Affects CoreAudio |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-43676: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebKit |
|||||||
| x | x | ||||||
| CVE-2026-43681: A local user may be able to read kernel memory. Affects AppleRAID |
|||||||
| x | x | x | |||||
| CVE-2026-43682: A remote user may be able to cause unexpected system termination or corrupt kernel memory. Affects HFS |
|||||||
| x | x | x | |||||
| CVE-2026-43693: An app may be able to gain root privileges. Affects Core Services |
|||||||
| x | x | x | |||||
| CVE-2026-43694: An app may be able to cause unexpected system termination or write kernel memory. Affects quarantine |
|||||||
| x | x | x | |||||
| CVE-2026-43698: An app may be able to gain root privileges. Affects CUPS |
|||||||
| x | x | x | |||||
| CVE-2026-43699: Processing maliciously crafted web content may lead to an unexpected process crash. Affects WebKit |
|||||||
| x | x | x | |||||
| CVE-2026-43700: Processing maliciously crafted web content may disclose sensitive user information. Affects WebKit |
|||||||
| x | x | x | |||||
| CVE-2026-43701: A malicious website may be able to process restricted web content outside the sandbox. Affects WebKit |
|||||||
| x | x | x | |||||
| CVE-2026-43703: Processing maliciously crafted web content may lead to an unexpected process crash. Affects libxslt |
|||||||
| x | x | x | x | x | |||
| CVE-2026-43704: A malicious web extension may be able to cause an unexpected process crash. Affects Web Extensions |
|||||||
| x | x | x | |||||
| CVE-2026-43705: Processing maliciously crafted web content may lead to memory corruption. Affects WebKit |
|||||||
| x | x | x | |||||
| CVE-2026-43706: Processing maliciously crafted web content may lead to an unexpected process crash. Affects libxslt |
|||||||
| x | x | x | x | x | |||
| CVE-2026-43707: Processing maliciously crafted web content may lead to an unexpected process crash. Affects WebKit |
|||||||
| x | x | x | |||||
| CVE-2026-43708: A malicious website may exfiltrate data cross-origin. Affects WebKit |
|||||||
| x | x | x | |||||
| CVE-2026-43710: An attacker may be able to cause unexpected system termination or corrupt kernel memory. Affects HFS |
|||||||
| x | x | x | |||||
| CVE-2026-43711: Processing a maliciously crafted video file may lead to unexpected app termination. Affects CoreMedia |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-43712: Processing maliciously crafted web content may lead to an unexpected process crash. Affects WebKit |
|||||||
| x | x | x | |||||
| CVE-2026-43713: Visiting a website may leak sensitive data. Affects WebKit |
|||||||
| x | x | x | |||||
| CVE-2026-43714: A malicious app may be able to access protected user data. Affects Foundation |
|||||||
| x | x | x | x | x | x | ||
| CVE-2026-43715: Processing maliciously crafted web content may lead to memory corruption. Affects WebKit |
|||||||
| x | x | x | |||||
| CVE-2026-43717: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebRTC |
|||||||
| x | x | ||||||
| CVE-2026-43718: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebRTC |
|||||||
| x | x | x | |||||
| CVE-2026-43721: A malicious website may be able to silently hijack clipboard data. Affects WebKit Storage |
|||||||
| x | x | x | |||||
| CVE-2026-43722: An app may be able to leak sensitive kernel state. Affects Kernel |
|||||||
| x | x | ||||||
| CVE-2026-43723: An app may be able to gain root privileges. Affects MediaRemote |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-43724: An app may be able to cause unexpected system termination or write kernel memory. Affects Kernel |
|||||||
| x | x | x | x | x | |||
| CVE-2026-43725: A malicious website may be able to process restricted web content outside the sandbox. Affects WebKit |
|||||||
| x | x | x | |||||
| CVE-2026-43728: An attacker may be able to modify the state of the Keychain. Affects Security |
|||||||
| x | |||||||
| CVE-2026-43729: Processing a maliciously crafted image may corrupt process memory. Affects Model I/O |
|||||||
| x | x | x | x | x | |||
| CVE-2026-43730: An app may be able to fingerprint the user. Affects AuthKit |
|||||||
| x | x | x | x | x | |||
| CVE-2026-43732: Processing maliciously crafted web content may disclose sensitive user information. Affects WebKit |
|||||||
| x | x | x | |||||
| CVE-2026-43735: A malicious website may exfiltrate data cross-origin. Affects WebKit |
|||||||
| x | x | x | |||||
| CVE-2026-43738: Processing a maliciously crafted asset catalog may result in disclosure of process memory. Affects CoreUI |
|||||||
| x | x | ||||||
| CVE-2026-43740: Processing maliciously crafted web content may result in the disclosure of process memory. Affects WebKit |
|||||||
| x | x | x | x | x | x | ||
| CVE-2026-43743: An app may be able to cause unexpected system termination. Affects IOGPUFamily |
|||||||
| x | x | ||||||
| CVE-2026-43744: Processing an audio stream in a maliciously crafted media file may terminate the process. Affects CoreAudio |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-43745: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebKit |
|||||||
| x | x | x | |||||
| CVE-2026-43747: Parsing a maliciously crafted file may lead to an unexpected app termination. Affects Disk Images |
|||||||
| x | x | x | |||||
| CVE-2026-43748: An app may be able to cause unexpected system termination. Affects Apple Neural Engine |
|||||||
| x | x | ||||||
| CVE-2026-43749: An app may be able to gain root privileges. Affects Accounts |
|||||||
| x | x | x | |||||
| CVE-2026-43750: An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges. Affects Wi?Fi |
|||||||
| x | x | x | |||||
| CVE-2026-43753: An attacker with physical access to a locked device may be able to view sensitive user information. Affects DriverKit |
|||||||
| x | x | x | x | ||||
| CVE-2026-43754: An app may be able to leak sensitive kernel state. Affects Kernel |
|||||||
| x | x | x | |||||
| CVE-2026-43755: An app may be able to gain root privileges. Affects SecurityAgent |
|||||||
| x | x | ||||||
| CVE-2026-43756: An app may be able to access user-sensitive data. Affects Control Center |
|||||||
| x | x | x | |||||
| CVE-2026-43757: An app may be able to cause unexpected system termination. Affects Kernel |
|||||||
| x | x | x | |||||
| CVE-2026-43758: An app may be able to access sensitive user data. Affects Data Detectors UI |
|||||||
| x | x | x | x | ||||
| CVE-2026-43759: An app may be able to access sensitive user data. Affects CoreMedia |
|||||||
| x | x | ||||||
| CVE-2026-43760: An app may be able to access user-sensitive data. Affects Screen Sharing Server |
|||||||
| x | x | ||||||
| CVE-2026-43763: An app may be able to read files outside of its sandbox. Affects ATS |
|||||||
| x | x | x | |||||
| CVE-2026-43764: An app may be able to cause unexpected system termination. Affects HFS |
|||||||
| x | x | x | |||||
| CVE-2026-43765: An app may be able to modify protected parts of the file system. Affects PackageKit |
|||||||
| x | x | x | |||||
| CVE-2026-43766: An attacker with physical access to a locked device may be able to view sensitive user information. Affects LoginWindow |
|||||||
| x | x | x | |||||
| CVE-2026-43767: An app may be able to cause unexpected system termination. Affects HFS |
|||||||
| x | x | x | |||||
| CVE-2026-43768: An app may be able to cause unexpected system termination. Affects udf |
|||||||
| x | x | x | |||||
| CVE-2026-43769: An app may be able to cause unexpected system termination. Affects Kernel |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-43770: An app may be able to access sensitive user data. Affects StorageKit |
|||||||
| x | x | x | x | ||||
| CVE-2026-43771: An app may be able to cause a denial-of-service. Affects Net-SNMP |
|||||||
| x | x | x | |||||
| CVE-2026-43772: An app may be able to break out of its sandbox. Affects NetFSFramework |
|||||||
| x | x | x | |||||
| CVE-2026-43773: Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory. Affects HFS |
|||||||
| x | x | x | |||||
| CVE-2026-43774: An app may be able to access sensitive user data. Affects Spotlight |
|||||||
| x | x | x | |||||
| CVE-2026-43775: An app may be able to access sensitive user data. Affects CoreMedia |
|||||||
| x | |||||||
| CVE-2026-43776: Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution. Affects AppleDouble |
|||||||
| x | x | x | |||||
| CVE-2026-43777: A remote attacker may be able to cause a denial of service. Affects Screen Sharing Server |
|||||||
| x | x | x | |||||
| CVE-2026-43778: An app may be able to cause unexpected system termination or corrupt kernel memory. Affects Kernel |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-43779: An app may be able to intercept network connections intended for another process. Affects Screen Sharing Server |
|||||||
| x | x | x | |||||
| CVE-2026-43780: Processing a maliciously crafted texture may lead to unexpected app termination. Affects ImageIO |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-43781: An app may be able to access sensitive user data. Affects Apple Account |
|||||||
| x | x | x | |||||
| CVE-2026-43782: An app may be able to access sensitive user data. Affects Kernel |
|||||||
| x | x | x | |||||
| CVE-2026-43792: An app may be able to access sensitive user data. Affects Safari |
|||||||
| x | x | ||||||
| CVE-2026-43793: An app may be able to cause unexpected system termination. Affects DriverKit |
|||||||
| x | x | x | |||||
| CVE-2026-43796: An app may be able to access sensitive user data. Affects Game Center |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-43797: An app may be able to access information about a user's contacts. Affects Contacts |
|||||||
| x | x | ||||||
| CVE-2026-43799: An app may be able to cause unexpected system termination. Affects Kernel |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-43800: An app may be able to access sensitive user data. Affects Siri |
|||||||
| x | x | x | x | ||||
| CVE-2026-43801: An app may be able to access sensitive user data. Affects App Store |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-43802: An app may be able to cause unexpected system termination. Affects CoreVideo |
|||||||
| x | x | x | |||||
| CVE-2026-43803: A remote attacker may be able to cause unexpected system termination. Affects CoreAudio |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-43804: Visiting a website may lead to an app denial-of-service. Affects WebKit |
|||||||
| x | x | x | x | ||||
| CVE-2026-43805: An app may be able to cause unexpected system termination or write kernel memory. Affects IOKit |
|||||||
| x | x | x | x | x | |||
| CVE-2026-43806: A local attacker may be able to cause a denial of service. Affects mDNSResponder |
|||||||
| x | |||||||
| CVE-2026-43807: A malicious accessory may be able to cause unexpected app termination. Affects MobileAccessoryUpdater |
|||||||
| x | x | x | x | x | |||
| CVE-2026-43810: A remote user may be able to cause unexpected system termination or corrupt kernel memory. Affects Kernel |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-43811: An app may be able to modify protected parts of the file system. Affects Books |
|||||||
| x | |||||||
| CVE-2026-43812: An app may be able to cause unexpected system termination. Affects Pro Res |
|||||||
| x | x | x | x | x | |||
| CVE-2026-43813: A maliciously crafted app may be able to bypass code signing enforcement. Affects CloudAttestation |
|||||||
| x | x | x | x | x | |||
| CVE-2026-43816: An app may be able to cause unexpected system termination. Affects Kernel |
|||||||
| x | x | x | x | x | |||
| CVE-2026-43817: An app may be able to cause unexpected system termination. Affects Kernel |
|||||||
| x | x | x | x | ||||
| CVE-2026-43818: Processing a maliciously crafted image may lead to arbitrary code execution. Affects ImageIO |
|||||||
| x | x | x | x | ||||
| CVE-2026-43819: An app may be able to access sensitive user data. Affects Accounts |
|||||||
| x | |||||||
| CVE-2026-43821: An app may be able to read files outside of its sandbox. Affects WebKit |
|||||||
| x | x | x | x | x | x | ||
| CVE-2026-64691: An app may be able to cause unexpected system termination. Affects GPU Drivers |
|||||||
| x | |||||||
| CVE-2026-64692: An app may be able to cause a denial-of-service. Affects Heimdal |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-64693: Processing a maliciously crafted image may lead to a denial-of-service. Affects ImageIO |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-64694: An app may be able to cause unexpected system termination. Affects Disk Images |
|||||||
| x | x | x | |||||
| CVE-2026-64695: A remote user may be able to cause unexpected system termination or corrupt kernel memory. Affects APFS |
|||||||
| x | x | x | |||||
| CVE-2026-64696: A remote user may be able to cause unexpected system termination or corrupt kernel memory. Affects SMB |
|||||||
| x | x | x | |||||
| CVE-2026-64697: An app may be able to cause unexpected system termination or corrupt kernel memory. Affects HFS |
|||||||
| x | x | x | |||||
| CVE-2026-64698: An app may be able to cause unexpected system termination or read kernel memory. Affects cd9660 |
|||||||
| x | x | x | |||||
| CVE-2026-64699: An app may be able to disclose kernel memory. Affects WebDAV |
|||||||
| x | x | x | |||||
| CVE-2026-64702: An app may be able to break out of its sandbox. Affects Audio |
|||||||
| x | x | x | |||||
| CVE-2026-64703: An app may be able to cause a denial-of-service. Affects WebDAV |
|||||||
| x | x | x | |||||
| CVE-2026-64704: An app may be able to cause unexpected system termination. Affects SMB |
|||||||
| x | x | x | |||||
| CVE-2026-64707: An app may be able to delete files for which it does not have permission. Affects BackgroundAssets |
|||||||
| x | x | x | x | x | |||
| CVE-2026-64708: An app may bypass Gatekeeper checks. Affects DesktopServices |
|||||||
| x | x | x | |||||
| CVE-2026-64709: An app may be able to disclose kernel memory. Affects Kernel |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-64710: An app may be able to leak sensitive user information. Affects Crash Reporter |
|||||||
| x | x | x | |||||
| CVE-2026-64711: An app may be able to leak sensitive user information. Affects NSColorPanel |
|||||||
| x | x | x | x | ||||
| CVE-2026-64713: Websites may know if the user has visited a given link. Affects WebKit |
|||||||
| x | x | x | x | x | x | ||
| CVE-2026-64716: Processing a maliciously crafted image may corrupt process memory. Affects ImageIO |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-64718: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebKit Canvas |
|||||||
| x | x | x | x | x | x | ||
| CVE-2026-64719: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebRTC |
|||||||
| x | x | x | x | x | x | ||
| CVE-2026-64720: An app may be able to cause unexpected system termination. Affects Kernel |
|||||||
| x | x | x | x | ||||
| CVE-2026-64721: An app may be able to access sensitive user data. Affects Kernel |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-64722: Processing a 3D model may result in disclosure of process memory. Affects Model I/O |
|||||||
| x | x | x | |||||
| CVE-2026-64723: An app may be able to access sensitive user data. Affects Kernel |
|||||||
| x | x | x | |||||
| CVE-2026-64724: An attacker on the local network may be able to cause a denial-of-service. Affects mDNSResponder |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-64725: An app may be able to cause a denial-of-service. Affects Audio |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-64726: An attacker in physical proximity may be able to corrupt process memory. Affects Wi-Fi |
|||||||
| x | x | x | x | x | |||
| CVE-2026-64727: An app may be able to cause unexpected system termination. Affects Kernel |
|||||||
| x | x | ||||||
| CVE-2026-64728: Maliciously crafted web content may violate iframe sandboxing policy. Affects WebKit |
|||||||
| x | x | x | x | x | x | ||
| CVE-2026-64730: Visiting a website that frames malicious content may lead to UI spoofing. Affects WebKit |
|||||||
| x | x | x | x | x | x | ||
| CVE-2026-64731: A malicious app may be able to break out of its sandbox. Affects Printing |
|||||||
| x | x | ||||||
| CVE-2026-64732: An attacker with physical access may be able to access sensitive user data during iPhone Mirroring. Affects Accessibility |
|||||||
| x | |||||||
| CVE-2026-64733: An app may be able to fingerprint the user. Affects Accounts Framework |
|||||||
| x | x | x | x | x | |||
| CVE-2026-64734: Processing a maliciously crafted contact may leak sensitive data. Affects Contacts |
|||||||
| x | x | x | x | x | x | ||
| CVE-2026-64735: A remote attacker may be able to bypass network filters. Affects Kernel |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-64737: A malicious app may be able to break out of its sandbox. Affects Apple Account |
|||||||
| x | x | x | |||||
| CVE-2026-64738: A malicious app may be able to break out of its sandbox. Affects Maps |
|||||||
| x | x | x | |||||
| CVE-2026-64739: An attacker may be able to cause unexpected app termination. Affects Libnotify |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-64740: A malicious app may be able to break out of its sandbox. Affects Game Center |
|||||||
| x | x | x | x | x | |||
| CVE-2026-64741: An app may be able to read a persistent device identifier. Affects Sandbox Profiles |
|||||||
| x | x | x | x | ||||
| CVE-2026-64742: An app may be able to access sensitive user data. Affects FrontBoard |
|||||||
| x | x | x | x | ||||
| CVE-2026-64743: An app may be able to access sensitive user data. Affects Managed Configuration |
|||||||
| x | x | x | x | x | |||
| CVE-2026-64744: An app may be able to disclose kernel memory. Affects Kernel |
|||||||
| x | x | x | |||||
| CVE-2026-64745: A person with physical access to a locked device may be able to access contacts and photos. Affects Siri |
|||||||
| x | x | ||||||
| CVE-2026-64746: An app may be able to add contacts without user authorization. Affects Contacts |
|||||||
| x | x | x | x | ||||
| CVE-2026-64747: An app may be able to execute arbitrary code with kernel privileges. Affects AVEVideoEncoder |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-64749: An app may be able to cause unexpected system termination or corrupt kernel memory. Affects Kernel |
|||||||
| x | x | x | x | ||||
| CVE-2026-64751: An app may be able to cause unexpected system termination or write kernel memory. Affects Kernel |
|||||||
| x | x | x | x | x | |||
| CVE-2026-64754: Processing a maliciously crafted file may lead to a denial-of-service. Affects ImageIO |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-64755: An app may be able to access sensitive user data. Affects WorkoutKit |
|||||||
| x | |||||||
| CVE-2026-64757: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebKit |
|||||||
| x | x | x | x | x | |||
| CVE-2026-64758: Processing a maliciously crafted file may lead to unexpected app termination. Affects ImageIO |
|||||||
| x | x | x | x | x | |||
| CVE-2026-64762: An app may be able to cause unexpected system termination. Affects AVEVideoEncoder |
|||||||
| x | x | x | |||||
| CVE-2026-64763: Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution. Affects SceneKit |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-64764: Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution. Affects SceneKit |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-64765: Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution. Affects SceneKit |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-64767: A remote attacker may be able to cause unexpected system termination or corrupt kernel memory. Affects afpfs |
|||||||
| x | x | x | |||||
| CVE-2026-64768: A remote attacker may cause an unexpected app termination. Affects Model I/O |
|||||||
| x | x | x | x | x | x | ||
| CVE-2026-64769: A remote attacker may be able to cause unexpected application termination or heap corruption. Affects Model I/O |
|||||||
| x | x | x | x | x | x | ||
| CVE-2026-64771: A remote attacker may be able to cause unexpected application termination or heap corruption. Affects Model I/O |
|||||||
| x | x | x | x | x | |||
| CVE-2026-64772: A remote attacker may be able to cause unexpected application termination or heap corruption. Affects Model I/O |
|||||||
| x | x | x | x | x | |||
| CVE-2026-64774: A remote attacker may be able to cause unexpected application termination or heap corruption. Affects Model I/O |
|||||||
| x | x | x | x | x | x | ||
| CVE-2026-64775: An app may be able to cause unexpected system termination. Affects Kernel |
|||||||
| x | x | x | x | x | x | x | |
| CVE-2026-64776: An app may be able to disclose kernel memory. Affects Disk Images |
|||||||
| x | x | x | |||||
| CVE-2026-64783: Processing maliciously crafted web content may lead to an unexpected Safari crash. Affects WebKit |
|||||||
| x | x | x | x | x |
--
Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu
Twitter|
Comments
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.