| CVE-2026-64732 |
Accessibility |
An attacker with physical access may be able to access sensitive user data during iPhone Mirroring |
Yes | No | No | No | No | No | No | No |
| CVE-2026-43749 |
Accounts |
An app may be able to gain root privileges |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-43819 |
Accounts |
An app may be able to access sensitive user data |
No | Yes | No | No | No | No | No | No |
| CVE-2026-64733 |
Accounts Framework |
An app may be able to fingerprint the user |
Yes | Yes | No | No | Yes | Yes | Yes | No |
| CVE-2026-64767 |
afpfs |
A remote attacker may be able to cause unexpected system termination or corrupt kernel memory |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-23918 |
apache |
A remote attacker may be able to cause a denial-of-service |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-64695 |
APFS |
A remote user may be able to cause unexpected system termination or corrupt kernel memory |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-43801 |
App Store |
An app may be able to access sensitive user data |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-43781 |
Apple Account |
An app may be able to access sensitive user data |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-64737 |
Apple Account |
A malicious app may be able to break out of its sandbox |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-28928 |
Apple Neural Engine |
An app may be able to cause unexpected system termination |
Yes | Yes | No | No | Yes | Yes | No | No |
| CVE-2026-43748 |
Apple Neural Engine |
An app may be able to cause unexpected system termination |
No | Yes | Yes | No | No | No | No | No |
| CVE-2026-43776 |
AppleDouble |
Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution |
Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-43681 |
AppleRAID |
A local user may be able to read kernel memory |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-43672 |
Assets |
A malicious application may be able to bypass Privacy preferences |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-43763 |
ATS |
An app may be able to read files outside of its sandbox |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-64702 |
Audio |
An app may be able to break out of its sandbox |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-64725 |
Audio |
An app may be able to cause a denial-of-service |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-43730 |
AuthKit |
An app may be able to fingerprint the user |
Yes | Yes | No | No | Yes | Yes | Yes | No |
| CVE-2026-64747 |
AVEVideoEncoder |
An app may be able to execute arbitrary code with kernel privileges |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-64762 |
AVEVideoEncoder |
An app may be able to cause unexpected system termination |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-64707 |
BackgroundAssets |
An app may be able to delete files for which it does not have permission |
Yes | Yes | Yes | Yes | No | No | Yes | No |
| CVE-2026-28849 |
BOM |
A maliciously crafted ZIP archive may bypass Gatekeeper checks |
No | No | Yes | Yes | No | No | No | No |
| CVE-2026-43811 |
Books |
An app may be able to modify protected parts of the file system |
Yes | No | No | No | No | No | No | No |
| CVE-2026-64698 |
cd9660 |
An app may be able to cause unexpected system termination or read kernel memory |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-43813 |
CloudAttestation |
A maliciously crafted app may be able to bypass code signing enforcement |
Yes | Yes | No | No | Yes | Yes | Yes | No |
| CVE-2026-43797 |
Contacts |
An app may be able to access information about a user's contacts |
Yes | Yes | No | No | No | No | No | No |
| CVE-2026-64734 |
Contacts |
Processing a maliciously crafted contact may leak sensitive data |
Yes | Yes | Yes | Yes | No | Yes | Yes | No |
| CVE-2026-64746 |
Contacts |
An app may be able to add contacts without user authorization |
Yes | Yes | No | No | No | Yes | Yes | No |
| CVE-2026-43756 |
Control Center |
An app may be able to access user-sensitive data |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-43693 |
Core Services |
An app may be able to gain root privileges |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-43673 |
CoreAudio |
Processing a maliciously crafted audio file may corrupt process memory |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-43744 |
CoreAudio |
Processing an audio stream in a maliciously crafted media file may terminate the process |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-43803 |
CoreAudio |
A remote attacker may be able to cause unexpected system termination |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-43711 |
CoreMedia |
Processing a maliciously crafted video file may lead to unexpected app termination |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-43759 |
CoreMedia |
An app may be able to access sensitive user data |
No | Yes | No | No | No | Yes | No | No |
| CVE-2026-43775 |
CoreMedia |
An app may be able to access sensitive user data |
No | Yes | Yes | No | No | No | No | No |
| CVE-2026-28936 |
CoreServices |
Processing a maliciously crafted file may lead to unexpected app termination |
No | No | Yes | Yes | No | No | No | No |
| CVE-2026-43738 |
CoreUI |
Processing a maliciously crafted asset catalog may result in disclosure of process memory |
No | No | Yes | Yes | No | No | No | No |
| CVE-2026-43802 |
CoreVideo |
An app may be able to cause unexpected system termination |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-64710 |
Crash Reporter |
An app may be able to leak sensitive user information |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-39875 |
CUPS |
A malicious app may be able to gain root privileges |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-43698 |
CUPS |
An app may be able to gain root privileges |
No | No | Yes | Yes | No | No | No | No |
| CVE-2026-3783 |
curl |
Authentication credentials may be sent to a server on another origin |
Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-3784 |
curl |
Authentication credentials may be sent to a server on another origin |
Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| CVE-2026-43758 |
Data Detectors UI |
An app may be able to access sensitive user data |
No | Yes | Yes | Yes | No | Yes | No | No |
| CVE-2026-64708 |
DesktopServices |
An app may bypass Gatekeeper checks |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-28926 |
Disk Images |
An app may be able to elevate privileges |
No | No | Yes | Yes | No | No | No | No |
| CVE-2026-28945 |
Disk Images |
An app may be able to bypass network restrictions |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-43747 |
Disk Images |
Parsing a maliciously crafted file may lead to an unexpected app termination |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-64694 |
Disk Images |
An app may be able to cause unexpected system termination |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-64776 |
Disk Images |
An app may be able to disclose kernel memory |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-43753 |
DriverKit |
An attacker with physical access to a locked device may be able to view sensitive user information |
Yes | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-43793 |
DriverKit |
An app may be able to cause unexpected system termination |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-43714 |
Foundation |
A malicious app may be able to access protected user data |
Yes | Yes | Yes | Yes | No | Yes | Yes | No |
| CVE-2026-64742 |
FrontBoard |
An app may be able to access sensitive user data |
Yes | No | No | No | Yes | Yes | Yes | No |
| CVE-2026-43796 |
Game Center |
An app may be able to access sensitive user data |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-64740 |
Game Center |
A malicious app may be able to break out of its sandbox |
Yes | Yes | Yes | Yes | Yes | No | No | No |
| CVE-2026-64691 |
GPU Drivers |
An app may be able to cause unexpected system termination |
No | Yes | No | No | No | No | No | No |
| CVE-2026-64692 |
Heimdal |
An app may be able to cause a denial-of-service |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-28981 |
HFS |
Processing a maliciously crafted image may lead to arbitrary code execution |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-43682 |
HFS |
A remote user may be able to cause unexpected system termination or corrupt kernel memory |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-43710 |
HFS |
An attacker may be able to cause unexpected system termination or corrupt kernel memory |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-43764 |
HFS |
An app may be able to cause unexpected system termination |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-43767 |
HFS |
An app may be able to cause unexpected system termination |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-43773 |
HFS |
Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-64697 |
HFS |
An app may be able to cause unexpected system termination or corrupt kernel memory |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2025-43325 |
Icons |
An app may be able to access sensitive user data |
No | No | Yes | Yes | No | No | No | No |
| CVE-2026-43661 |
ImageIO |
Processing a maliciously crafted image may corrupt process memory |
No | No | Yes | Yes | No | No | No | No |
| CVE-2026-43780 |
ImageIO |
Processing a maliciously crafted texture may lead to unexpected app termination |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-43818 |
ImageIO |
Processing a maliciously crafted image may lead to arbitrary code execution |
Yes | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-64693 |
ImageIO |
Processing a maliciously crafted image may lead to a denial-of-service |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-64716 |
ImageIO |
Processing a maliciously crafted image may corrupt process memory |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-64754 |
ImageIO |
Processing a maliciously crafted file may lead to a denial-of-service |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-64758 |
ImageIO |
Processing a maliciously crafted file may lead to unexpected app termination |
Yes | Yes | No | No | Yes | Yes | Yes | No |
| CVE-2026-43743 |
IOGPUFamily |
An app may be able to cause unexpected system termination |
No | No | No | No | Yes | Yes | No | No |
| CVE-2026-43805 |
IOKit |
An app may be able to cause unexpected system termination or write kernel memory |
Yes | Yes | Yes | Yes | No | Yes | No | No |
| CVE-2026-39877 |
IOSkywalkFamily |
An app may be able to disclose kernel memory |
No | No | Yes | Yes | No | No | No | No |
| CVE-2026-28931 |
Kernel |
Connecting to a malicious NFS server may lead to kernel memory corruption |
Yes | Yes | No | No | Yes | Yes | No | No |
| CVE-2026-28982 |
Kernel |
A remote user may be able to cause unexpected system termination or corrupt kernel memory |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-39868 |
Kernel |
An app may be able to cause unexpected system termination or corrupt kernel memory |
No | No | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-43722 |
Kernel |
An app may be able to leak sensitive kernel state |
No | No | Yes | Yes | No | No | No | No |
| CVE-2026-43724 |
Kernel |
An app may be able to cause unexpected system termination or write kernel memory |
No | No | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-43739 |
Kernel |
An app may be able to cause unexpected system termination |
Yes | Yes | No | No | Yes | Yes | Yes | No |
| CVE-2026-43754 |
Kernel |
An app may be able to leak sensitive kernel state |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-43757 |
Kernel |
An app may be able to cause unexpected system termination |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-43769 |
Kernel |
An app may be able to cause unexpected system termination |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-43778 |
Kernel |
An app may be able to cause unexpected system termination or corrupt kernel memory |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-43782 |
Kernel |
An app may be able to access sensitive user data |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-43799 |
Kernel |
An app may be able to cause unexpected system termination |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-43809 |
Kernel |
An app may be able to cause unexpected system termination |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-43810 |
Kernel |
A remote user may be able to cause unexpected system termination or corrupt kernel memory |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-43814 |
Kernel |
An app may be able to cause unexpected system termination |
Yes | Yes | No | No | Yes | Yes | No | No |
| CVE-2026-43816 |
Kernel |
An app may be able to cause unexpected system termination |
Yes | Yes | No | No | Yes | Yes | Yes | No |
| CVE-2026-43817 |
Kernel |
An app may be able to cause unexpected system termination |
Yes | Yes | No | No | Yes | Yes | Yes | No |
| CVE-2026-43822 |
Kernel |
An app may be able to cause unexpected system termination |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-64700 |
Kernel |
An app may be able to cause unexpected system termination |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-64709 |
Kernel |
An app may be able to disclose kernel memory |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-64720 |
Kernel |
An app may be able to cause unexpected system termination |
Yes | Yes | No | No | Yes | Yes | No | No |
| CVE-2026-64721 |
Kernel |
An app may be able to access sensitive user data |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-64723 |
Kernel |
An app may be able to access sensitive user data |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-64727 |
Kernel |
An app may be able to cause unexpected system termination |
No | Yes | No | No | Yes | No | No | No |
| CVE-2026-64729 |
Kernel |
An app may be able to cause unexpected system termination |
Yes | Yes | No | No | Yes | Yes | Yes | No |
| CVE-2026-64735 |
Kernel |
A remote attacker may be able to bypass network filters |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-64744 |
Kernel |
An app may be able to disclose kernel memory |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-64749 |
Kernel |
An app may be able to cause unexpected system termination or corrupt kernel memory |
Yes | Yes | Yes | No | No | No | Yes | No |
| CVE-2026-64751 |
Kernel |
An app may be able to cause unexpected system termination or write kernel memory |
Yes | Yes | No | No | Yes | Yes | Yes | No |
| CVE-2026-64775 |
Kernel |
An app may be able to cause unexpected system termination |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-20672 |
LaunchServices |
An app may be able to access sensitive user data |
No | No | Yes | Yes | No | No | No | No |
| CVE-2026-28983 |
LaunchServices |
A remote attacker may be able to cause a denial of service |
No | No | Yes | Yes | No | No | No | No |
| CVE-2026-28900 |
libarchive |
A maliciously crafted ZIP archive may bypass Gatekeeper checks |
No | No | Yes | Yes | No | No | No | No |
| CVE-2026-4424 |
libarchive |
Processing a maliciously crafted file may result in disclosure of process memory |
Yes | Yes | Yes | Yes | No | No | Yes | No |
| CVE-2026-28973 |
libc |
A malicious app may be able to break out of its sandbox |
Yes | Yes | Yes | Yes | No | Yes | No | No |
| CVE-2026-64739 |
Libnotify |
An attacker may be able to cause unexpected app termination |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-43703 |
libxslt |
Processing maliciously crafted web content may lead to an unexpected process crash |
No | No | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-43706 |
libxslt |
Processing maliciously crafted web content may lead to an unexpected process crash |
No | No | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-43766 |
LoginWindow |
An attacker with physical access to a locked device may be able to view sensitive user information |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-64743 |
Managed Configuration |
An app may be able to access sensitive user data |
Yes | Yes | No | No | Yes | Yes | Yes | No |
| CVE-2026-64738 |
Maps |
A malicious app may be able to break out of its sandbox |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-43653 |
mDNSResponder |
An attacker on the local network may be able to cause a denial-of-service |
No | No | Yes | No | No | No | No | No |
| CVE-2026-43806 |
mDNSResponder |
A local attacker may be able to cause a denial of service |
No | Yes | No | No | No | No | No | No |
| CVE-2026-64724 |
mDNSResponder |
An attacker on the local network may be able to cause a denial-of-service |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-43723 |
MediaRemote |
An app may be able to gain root privileges |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-28911 |
Metal |
A malicious app may be able to corrupt memory of a system process |
No | Yes | No | Yes | No | No | No | No |
| CVE-2026-43807 |
MobileAccessoryUpdater |
A malicious accessory may be able to cause unexpected app termination |
No | No | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-43729 |
Model I/O |
Processing a maliciously crafted image may corrupt process memory |
Yes | Yes | Yes | No | Yes | No | Yes | No |
| CVE-2026-43733 |
Model I/O |
Processing a maliciously crafted image may corrupt process memory |
Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-64722 |
Model I/O |
Processing a 3D model may result in disclosure of process memory |
Yes | Yes | Yes | No | No | No | No | No |
| CVE-2026-64768 |
Model I/O |
A remote attacker may cause an unexpected app termination |
Yes | Yes | Yes | Yes | Yes | No | Yes | No |
| CVE-2026-64769 |
Model I/O |
A remote attacker may be able to cause unexpected application termination or heap corruption |
Yes | Yes | Yes | Yes | Yes | No | Yes | No |
| CVE-2026-64770 |
Model I/O |
A remote attacker may be able to cause unexpected application termination or heap corruption |
Yes | Yes | Yes | Yes | Yes | No | Yes | No |
| CVE-2026-64771 |
Model I/O |
A remote attacker may be able to cause unexpected application termination or heap corruption |
Yes | Yes | Yes | No | Yes | No | Yes | No |
| CVE-2026-64772 |
Model I/O |
A remote attacker may be able to cause unexpected application termination or heap corruption |
Yes | Yes | Yes | No | Yes | No | Yes | No |
| CVE-2026-64774 |
Model I/O |
A remote attacker may be able to cause unexpected application termination or heap corruption |
Yes | Yes | Yes | Yes | Yes | No | Yes | No |
| CVE-2026-43771 |
Net-SNMP |
An app may be able to cause a denial-of-service |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-43772 |
NetFSFramework |
An app may be able to break out of its sandbox |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-28961 |
Network Extensions |
An attacker with physical access to a locked device may be able to view sensitive user information |
No | No | Yes | Yes | No | No | No | No |
| CVE-2026-64711 |
NSColorPanel |
An app may be able to leak sensitive user information |
Yes | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-28912 |
PackageKit |
A user may be able to elevate privileges |
No | Yes | Yes | No | No | No | No | No |
| CVE-2026-43765 |
PackageKit |
An app may be able to modify protected parts of the file system |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-28896 |
ppp |
An attacker may be able to cause unexpected system termination or read kernel memory |
No | No | Yes | Yes | No | No | No | No |
| CVE-2026-64731 |
Printing |
A malicious app may be able to break out of its sandbox |
No | Yes | Yes | No | No | No | No | No |
| CVE-2026-43812 |
Pro Res |
An app may be able to cause unexpected system termination |
Yes | Yes | Yes | No | Yes | No | Yes | No |
| CVE-2026-43694 |
quarantine |
An app may be able to cause unexpected system termination or write kernel memory |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-39874 |
Remote Management |
A malicious app may be able to gain root privileges |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-43792 |
Safari |
An app may be able to access sensitive user data |
No | Yes | No | No | No | No | No | Yes |
| CVE-2026-64741 |
Sandbox Profiles |
An app may be able to read a persistent device identifier |
Yes | No | No | No | Yes | Yes | Yes | No |
| CVE-2026-64763 |
SceneKit |
Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-64764 |
SceneKit |
Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-64765 |
SceneKit |
Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-64766 |
SceneKit |
Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution |
Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| CVE-2026-43665 |
Screen Sharing Server |
A local attacker may be able to determine the legacy VNC password configured for Screen Sharing |
No | No | Yes | Yes | No | No | No | No |
| CVE-2026-43760 |
Screen Sharing Server |
An app may be able to access user-sensitive data |
No | Yes | No | Yes | No | No | No | No |
| CVE-2026-43777 |
Screen Sharing Server |
A remote attacker may be able to cause a denial of service |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-43779 |
Screen Sharing Server |
An app may be able to intercept network connections intended for another process |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-43728 |
Security |
An attacker may be able to modify the state of the Keychain |
No | Yes | No | No | No | No | No | No |
| CVE-2026-43755 |
SecurityAgent |
An app may be able to gain root privileges |
No | Yes | No | Yes | No | No | No | No |
| CVE-2026-43800 |
Siri |
An app may be able to access sensitive user data |
Yes | Yes | No | No | Yes | Yes | No | No |
| CVE-2026-64745 |
Siri |
A person with physical access to a locked device may be able to access contacts and photos |
No | Yes | Yes | No | No | No | No | No |
| CVE-2026-39873 |
SMB |
Connecting to a malicious SMB server may lead to unexpected system termination |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-64696 |
SMB |
A remote user may be able to cause unexpected system termination or corrupt kernel memory |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-64704 |
SMB |
An app may be able to cause unexpected system termination |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-43774 |
Spotlight |
An app may be able to access sensitive user data |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-43770 |
StorageKit |
An app may be able to access sensitive user data |
No | Yes | Yes | Yes | Yes | No | No | No |
| CVE-2026-43768 |
udf |
An app may be able to cause unexpected system termination |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-43704 |
Web Extensions |
A malicious web extension may be able to cause an unexpected process crash |
No | No | No | No | Yes | Yes | Yes | No |
| CVE-2026-64699 |
WebDAV |
An app may be able to disclose kernel memory |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-64703 |
WebDAV |
An app may be able to cause a denial-of-service |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-39872 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected process crash |
No | No | No | No | Yes | Yes | Yes | No |
| CVE-2026-43663 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected process crash |
No | No | No | No | Yes | Yes | Yes | No |
| CVE-2026-43676 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected Safari crash |
No | No | No | No | No | Yes | Yes | No |
| CVE-2026-43699 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected process crash |
No | No | No | No | Yes | Yes | Yes | No |
| CVE-2026-43700 |
WebKit |
Processing maliciously crafted web content may disclose sensitive user information |
No | No | No | No | Yes | Yes | Yes | No |
| CVE-2026-43701 |
WebKit |
A malicious website may be able to process restricted web content outside the sandbox |
No | No | No | No | Yes | Yes | Yes | No |
| CVE-2026-43705 |
WebKit |
Processing maliciously crafted web content may lead to memory corruption |
No | No | No | No | Yes | Yes | Yes | No |
| CVE-2026-43707 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected process crash |
No | No | No | No | Yes | Yes | Yes | No |
| CVE-2026-43708 |
WebKit |
A malicious website may exfiltrate data cross-origin |
No | No | No | No | Yes | Yes | Yes | No |
| CVE-2026-43709 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected process crash |
No | No | No | No | Yes | Yes | Yes | No |
| CVE-2026-43712 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected process crash |
No | No | No | No | Yes | Yes | Yes | No |
| CVE-2026-43713 |
WebKit |
Visiting a website may leak sensitive data |
No | No | No | No | Yes | Yes | Yes | No |
| CVE-2026-43715 |
WebKit |
Processing maliciously crafted web content may lead to memory corruption |
No | No | No | No | Yes | Yes | Yes | No |
| CVE-2026-43725 |
WebKit |
A malicious website may be able to process restricted web content outside the sandbox |
No | No | No | No | Yes | Yes | Yes | No |
| CVE-2026-43726 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected process crash |
No | No | No | No | Yes | Yes | Yes | No |
| CVE-2026-43727 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected Safari crash |
No | No | No | No | No | Yes | Yes | No |
| CVE-2026-43731 |
WebKit |
Processing maliciously crafted web content may lead to memory corruption |
No | No | No | No | Yes | Yes | Yes | No |
| CVE-2026-43732 |
WebKit |
Processing maliciously crafted web content may disclose sensitive user information |
No | No | No | No | Yes | Yes | Yes | No |
| CVE-2026-43734 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected process crash |
No | No | No | No | Yes | Yes | Yes | No |
| CVE-2026-43735 |
WebKit |
A malicious website may exfiltrate data cross-origin |
No | No | No | No | Yes | Yes | Yes | No |
| CVE-2026-43740 |
WebKit |
Processing maliciously crafted web content may result in the disclosure of process memory |
Yes | No | No | No | Yes | Yes | Yes | Yes |
| CVE-2026-43742 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected process crash |
No | No | No | No | Yes | Yes | Yes | No |
| CVE-2026-43745 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected Safari crash |
No | No | No | No | Yes | Yes | Yes | No |
| CVE-2026-43804 |
WebKit |
Visiting a website may lead to an app denial-of-service |
Yes | Yes | No | No | No | No | Yes | Yes |
| CVE-2026-43821 |
WebKit |
An app may be able to read files outside of its sandbox |
Yes | Yes | No | No | Yes | Yes | Yes | Yes |
| CVE-2026-64713 |
WebKit |
Websites may know if the user has visited a given link |
Yes | Yes | No | No | Yes | Yes | Yes | Yes |
| CVE-2026-64728 |
WebKit |
Maliciously crafted web content may violate iframe sandboxing policy |
Yes | Yes | No | No | Yes | Yes | Yes | Yes |
| CVE-2026-64730 |
WebKit |
Visiting a website that frames malicious content may lead to UI spoofing |
Yes | Yes | No | No | Yes | Yes | Yes | Yes |
| CVE-2026-64757 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected Safari crash |
Yes | Yes | No | No | No | Yes | Yes | Yes |
| CVE-2026-64783 |
WebKit |
Processing maliciously crafted web content may lead to an unexpected Safari crash |
Yes | Yes | No | No | No | Yes | Yes | Yes |
| CVE-2026-43720 |
WebKit Canvas |
Processing maliciously crafted web content may lead to an unexpected Safari crash |
No | No | No | No | Yes | Yes | Yes | No |
| CVE-2026-64718 |
WebKit Canvas |
Processing maliciously crafted web content may lead to an unexpected Safari crash |
Yes | Yes | No | No | Yes | Yes | Yes | Yes |
| CVE-2026-43721 |
WebKit Storage |
A malicious website may be able to silently hijack clipboard data |
No | No | No | No | Yes | Yes | Yes | No |
| CVE-2026-28979 |
WebRTC |
Processing maliciously crafted web content may lead to an unexpected process crash |
No | No | No | No | Yes | Yes | Yes | No |
| CVE-2026-43717 |
WebRTC |
Processing maliciously crafted web content may lead to an unexpected Safari crash |
No | No | No | No | Yes | Yes | No | No |
| CVE-2026-43718 |
WebRTC |
Processing maliciously crafted web content may lead to an unexpected Safari crash |
No | No | No | No | Yes | Yes | Yes | No |
| CVE-2026-64719 |
WebRTC |
Processing maliciously crafted web content may lead to an unexpected Safari crash |
Yes | Yes | No | No | Yes | Yes | Yes | Yes |
| CVE-2026-43750 |
Wi-Fi |
An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-64726 |
Wi-Fi |
An attacker in physical proximity may be able to corrupt process memory |
Yes | Yes | No | No | Yes | Yes | Yes | No |
| CVE-2026-64755 |
WorkoutKit |
An app may be able to access sensitive user data |
Yes | No | No | No | No | No | No | No |
| CVE-2026-28932 |
xar |
An app may be able to cause a denial of service |
No | Yes | Yes | Yes | No | No | No | No |
| CVE-2026-28914 |
zip |
A maliciously crafted ZIP archive may bypass Gatekeeper checks |
No | No | Yes | Yes | No | No | No | No |