APPLE-SA-09-14-2026-3 macOS Golden Gate 27
Full Disclosuremailing list archivesFrom: Apple Product Security via Fulldisclos 2026-9-22 18:31:25 Author: seclists.org(查看原文) 阅读量:1 收藏

fulldisclosure logo

Full Disclosure mailing list archives


From: Apple Product Security via Fulldisclosure <fulldisclosure () seclists org>
Date: Mon, 14 Sep 2026 15:06:19 -0700

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

APPLE-SA-09-14-2026-3 macOS Golden Gate 27

macOS Golden Gate 27 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149035.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Accelerate Framework
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing a maliciously crafted image may lead to unexpected
process termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-86882: Peter Malone

Accessibility
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access sensitive user data
Description: This issue was addressed with improved data protection.
CVE-2026-43664: Stuart Wallace, Ilya Andr (andrd3v), Rosyna Keller of
Totally Not Malicious Software, CJ Vana, David Strnadel, Daniel Febrero,
Asaf Cohen, Gongyu Ma (@Mezone0), Jian Lee (@speedyfriend433)

Accounts
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: A malicious application may be able to bypass Privacy
preferences
Description: An authorization issue was addressed with improved state
management.
CVE-2026-65404: Arni Hardarson (Neonix Security), Vinay Kumar Rasala
(Xplo8E) from Appknox, Stuart Wallace, 이재영

APFS
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An application may be able to access restricted files
Description: A permissions issue was addressed with improved path
validation.
CVE-2026-86910: an anonymous researcher

APFS
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause unexpected system termination or
write kernel memory
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-84523: Cem Onat Karagun, an anonymous researcher

App Store
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: A local app may be able to read a persistent account identifier
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-86888: Zhongcheng Li (CK01)

AppKit
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access protected user data
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-84587: an anonymous researcher

Apple Account
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: A malicious application may be able to leak sensitive user
information
Description: An information disclosure issue was addressed with improved
state management.
CVE-2026-84586: Prashan Samarathunge, Zhongcheng Li (CK01)

Apple Account
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to use the Sign In With Apple authentication
flow to access the user's Apple Account
Description: An authentication issue was addressed with improved state
management.
CVE-2026-20683: Dem0ns (@天府简易信工作室), Abdelhak Kherroubi, Jasminder Pal
Singh, Lehan Dilusha Jayasingha (Sri Lanka)

Apple Intelligence
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to bypass Apple Intelligence security prompts
Description: A permissions issue was addressed with improved state
management.
CVE-2026-84601: Nick Cook, Sentry Flag

Apple Neural Engine
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause unexpected system termination
Description: An integer overflow was addressed with improved input
validation.
CVE-2026-65408: tamdao

AppleAVD
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause unexpected system termination
Description: A use after free issue was addressed with improved memory
management.
CVE-2026-65407: Franco Belman at Blackwing Intelligence

AppleDouble
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Mounting a disk image with maliciously crafted files may lead to
unexpected system termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-84519: Richard Zana

AppleFDEKeyStore
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: A local attacker may be able to cause unexpected system
termination or corrupt kernel memory
Description: A buffer overflow was addressed with improved size
validation.
CVE-2026-84520: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

AppleMobileFileIntegrity
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: A malicious app may be able to break out of its sandbox
Description: A validation issue existed in the entitlement verification.
This issue was addressed with improved validation of the process
entitlement.
CVE-2026-65381: Mickey Jin (@patch1t)

Archive Utility
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to break out of its sandbox
Description: This issue was addressed with improved handling of
symlinks.
CVE-2026-84584: Mickey Jin (@patch1t)

Archive Utility
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access sensitive user data
Description: A race condition was addressed with improved state
management.
CVE-2026-84522: Mickey Jin (@patch1t)

ATS
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access user-sensitive data
Description: A logging issue was addressed with improved data redaction.
CVE-2026-84525: D4rthL

ATS
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access sensitive user data
Description: A permissions issue was addressed with improved validation.
CVE-2026-65342: Ahmed Alwardani, Mohamad Dawoud / Abodi Dawoud

Authentication Services
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to delete credentials stored in Keychain
Description: This issue was addressed by removing the vulnerable code.
CVE-2026-86905: Ilya Andr (andrd3v)

AuthKit
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: A local app may be able to read a persistent account identifier
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-84583: Zhongcheng Li from IES Red Team

autofs
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to bypass Gatekeeper checks
Description: A logic issue was addressed with improved checks.
CVE-2026-84570: Mr.Gedik (@h4ck2s3c)

autofs
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An attacker with control of a network directory server may be
able to execute arbitrary code with root privileges
Description: A path traversal issue was addressed with improved path
validation.
CVE-2026-84568: Mr.Gedik (@h4ck2s3c) of Turkish Technology

Automator
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to break out of its sandbox
Description: An authorization issue was addressed with improved state
management.
CVE-2026-84535: Kun Peeks (@SwayZGl1tZyyy), Oren Yomtov, Morris Richman
(@morrisinlife), Sindre Sorhus

AVEVideoEncoder
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause unexpected system termination
Description: The issue was addressed with improved checks.
CVE-2026-65410: Calif.io in collaboration with Claude and Anthropic
Research

AVEVideoEncoder
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause unexpected system termination
Description: A type confusion issue was addressed with improved memory
handling.
CVE-2026-84616: Peter Malone

AVEVideoEncoder
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: A sandboxed app may be able to execute arbitrary code with
kernel privileges
Description: A race condition was addressed with improved state
management.
CVE-2026-84607: Ruslan Dautov

BackgroundAssets
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access sensitive user data
Description: A logic issue was addressed with improved validation.
CVE-2026-65406: Ye Zhang (@VAR10CK) of Baidu Security

Bluetooth
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: A remote attacker may be able to cause unexpected app
termination or arbitrary code execution
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-65414

Bluetooth
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may gain unauthorized access to Bluetooth
Description: An authorization issue was addressed with improved state
management.
CVE-2026-84560: an anonymous researcher

Bluetooth
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to gain root privileges
Description: This issue was addressed with additional entitlement
checks.
CVE-2026-84631: Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs

cd9660
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause unexpected system termination
Description: The issue was addressed with improved memory handling.
CVE-2026-84567: Sanny Mitra, Sihyun Roh (Compsec, SNU), ngockhanh from
Cystack, Ataberk Yavuzer, 정우 하 (@0xfa11babe), Kun Peeks
(@SwayZGl1tZyyy), Surej Sekhar, Suresh Sundaram, Hari Shanmugam (The
Hxr1)

copyfile
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An archive may be able to bypass Gatekeeper
Description: A file quarantine bypass was addressed with additional
checks.
CVE-2026-65399: Rishabh Jain (rjcyber) of cyberplanet, Pasquale Scola,
an anonymous researcher

Core Bluetooth
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access Bluetooth device information
Description: An authorization issue was addressed with improved state
management.
CVE-2026-86891: Dawuge of Shuffle Team

CoreDrag
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause unexpected process termination or
disclose process memory
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2026-43683: Nathaniel Oh (@calysteon)

CoreMedia
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access user-sensitive data
Description: An access issue was addressed with additional sandbox
restrictions.
CVE-2026-43789: 이재영

CoreMedia
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing a maliciously crafted image may lead to arbitrary
code execution
Description: A memory corruption issue was addressed by removing the
vulnerable code.
CVE-2026-64752: Nik Tsytsarkin

CoreMedia
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: A sandboxed process may be able to circumvent sandbox
restrictions
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-86876: Chris Bailey - Short Circuit

CoreMedia
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing a maliciously crafted video file may lead to
unexpected app termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-65344: Siyeong kim

CoreML
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: A sandboxed app may be able to access restricted files
Description: A permissions issue was addressed with improved path
validation.
CVE-2026-84624: AL Najafi, tamdao

CoreMotion
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access motion data from headphones without
user consent
Description: An authorization issue was addressed with improved
validation.
CVE-2026-43737: Stuart Wallace

CoreServices
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to bypass Privacy preferences
Description: A permissions issue was addressed with improved state
management.
CVE-2026-84574: Mickey Jin (@patch1t)

CoreServices
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: A malicious application may be able to access restricted files
Description: A permissions issue was addressed with improved validation.
CVE-2026-84559: Ryan Hughes

CoreServices
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to gain root privileges
Description: This issue was addressed with additional entitlement
checks.
CVE-2026-43786: Kujtim Kryeziu (Sentry)

CoreText
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing web content may lead to a denial-of-service
Description: A null pointer dereference was addressed with improved
input validation.
CVE-2026-65412: Pavan Nallamothu

CoreText
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing a maliciously crafted font may result in the
disclosure of process memory
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2026-84596: ret2happy, Meta Product Security

CoreUI
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing a maliciously crafted file may lead to unexpected app
termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-84575: Mustafa Calap (@ordinal0, dbg.re)

CoreUI
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause a denial of service
Description: A buffer overflow was addressed with improved bounds
checking.
CVE-2026-84489: stratan (@5tratan), Peter Malone

CoreUI
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing a maliciously crafted image may lead to unexpected
app termination
Description: A buffer overflow was addressed with improved bounds
checking.
CVE-2026-84571: stratan (@5tratan), Peter Malone

CoreUI
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing a maliciously crafted asset catalog may result in
disclosure of process memory
Description: The issue was addressed with improved memory handling.
CVE-2026-43738: Peter Malone

CoreUI
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing a maliciously crafted asset catalog may lead to
unexpected process termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-84511: Rahul Raj, stratan (@5tratan)

CUPS
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause unexpected system termination
Description: A logic issue was addressed with improved checks.
CVE-2026-84563: Yongyue WANG AKA Brian.W of OKX security, Omar Cerrito

CUPS
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An attacker in a privileged network position may be able to
cause a denial-of-service
Description: This is a vulnerability in open source code and Apple
Software is among the affected projects. The CVE-ID was assigned by a
third party. Learn more about the issue and CVE-ID at cve.org.
CVE-2026-34979: Tristan Madani (@TristanInSec) from Talence Security,
Юлия Мерцалова

CUPS
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to gain root privileges
Description: An injection issue was addressed with improved validation.
CVE-2026-43698: Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs

CUPS
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to gain elevated privileges
Description: A path handling issue was addressed with improved
validation.
CVE-2026-64790: Aaron Grattafiori - NVIDIA AI Red Team

CUPS
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: A remote user may cause an unexpected app termination or
arbitrary code execution
Description: A validation issue was addressed with improved input
sanitization.
CVE-2026-43692: Aaron Grattafiori - NVIDIA AI Red Team

CUPS
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An attacker in a privileged network position may be able to
cause a denial-of-service
Description: An integer overflow was addressed with improved input
validation.
CVE-2026-84554: Joseph Shamoon, Meshaal @ Darkcov

CUPS
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to gain root privileges
Description: A path handling issue was addressed with improved
validation.
CVE-2026-43691: Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs

CUPS
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An application may be able to access restricted files
Description: An input validation issue was addressed with improved input
validation.
CVE-2026-84541: 章鱼哥@aipy (aipyaipy.com)

CUPS
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state
management.
CVE-2026-84540: Yongyue WANG AKA Brian.W of OKX security, 章鱼哥@aipy
(aipyaipy.com), instantraaamen (github.com/instantraaamen) Contact:
masa.shiramizu () gmail com

CUPS
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing a maliciously crafted file may result in unexpected
app termination or disclosure of process memory
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2026-84516: 章鱼哥@aipy (aipyaipy.com)

DeviceCheck
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to read persistent device identifiers
Description: An authorization issue was addressed with improved access
control.
CVE-2026-84612: N.M.Praveen Nawarathne (@zblockrat), James Gill
(@[email protected])

Directory Utility
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to gain root privileges
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-84505: Tommy DeVoss from Braze Security Team (@thedawgyg)

Disk Images
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing a maliciously crafted disk image may lead to
unexpected app termination
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2026-84565: Nathaniel Oh (@calysteon)

Disk Images
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause unexpected system termination
Description: The issue was addressed with improved memory handling.
CVE-2026-84552: Tommy DeVoss from Braze Security Team (@thedawgyg),
flower xu, Adriatik Raci, PETOWORKS의 Bugeun Choi (@Bugeun), Peter
Malone, Daisuke Hatakeyama and Ryohei Ueki (@SYZD Research), Hyunwoo Kim
(@v4bel)

Disk Images
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause unexpected system termination
Description: A race condition was addressed with additional validation.
CVE-2026-84550: Daisuke Hatakeyama and Ryohei Ueki (@SYZD Research),
Hyunwoo Kim (@v4bel)

Disk Images
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to gain root privileges
Description: This issue was addressed with improved checks.
CVE-2026-65362: Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs,
Adriatik Raci, Manish Bhatt, Amazon Leo Security, Nathaniel Oh
(@calysteon)

Disk Images
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Mounting a maliciously crafted disk image may cause unexpected
system termination or corrupt kernel memory
Description: A buffer overflow was addressed with improved bounds
checking.
CVE-2026-84512: Daisuke Hatakeyama and Ryohei Ueki (@SYZD Research)

exFAT
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Mounting a maliciously crafted volume may lead to unexpected
system termination
Description: A heap buffer overflow was addressed with improved bounds
checking.
CVE-2026-84510: Meta Red Team X - Nik Tsytsarkin, Richard Zana

exFAT
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Mounting a maliciously crafted exFAT volume may cause unexpected
system termination or kernel memory disclosure
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-86901: an anonymous researcher

exFAT
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Mounting a maliciously crafted exFAT volume may cause unexpected
system termination or kernel memory disclosure
Description: An out-of-bounds read issue was addressed with improved
input validation.
CVE-2026-86900: ngockhanh from Cystack, an anonymous researcher

File Bookmark
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to modify a file it only had permission to
read
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-43785: Junyeong Lee (jylab.github.io), Merrick Hare, Aditya
Kumar, John Nzyuko Uvyu, Narendra Singh (@_3P1C)

file_cmds
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Extracting a maliciously crafted archive may allow an attacker
to write arbitrary files
Description: A path handling issue was addressed with improved
validation.
CVE-2026-84534: Geoffrey Lovelace

Filters
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing a maliciously crafted file may lead to unexpected app
termination
Description: A memory corruption issue was addressed with improved input
validation.
CVE-2026-43688: Peter Malone

FontParser
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing a maliciously crafted font file may lead to
unexpected app termination
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2026-84524: an anonymous researcher

FontParser
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing a maliciously crafted font may result in the
disclosure of process memory
Description: An out-of-bounds read issue was addressed with improved
input validation.
CVE-2026-84597: Nik Tsytsarkin

Foundation
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access sensitive user data
Description: An access issue was addressed with additional sandbox
restrictions on the system pasteboards.
CVE-2026-84569: Yurii Bakurov, Sindre Sorhus, Asaf Cohen

Foundation
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause a denial of service
Description: A type confusion issue was addressed with improved memory
handling.
CVE-2026-65409: Bruce Dang of Calif.io in collaboration with Claude and
Anthropic Research

Foundation
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: A malicious app may be able to bypass clickjacking protections
for secure prompts
Description: This issue was addressed with improved state management.
CVE-2026-86911: Ron Masas of BreakPoint.SH, an anonymous researcher

Game Center
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access sensitive user data
Description: A permissions issue was addressed with improved validation.
CVE-2026-84618: Luke Symons

Graphics
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause unexpected system termination
Description: A race condition was addressed with improved state
handling.
CVE-2026-84492: Tommy DeVoss from Braze Security Team (@thedawgyg),
Jiyong Yang

Heimdal
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An attacker in a privileged network position may be able to
modify network traffic
Description: A cryptographic issue was addressed with improved integrity
checks.
CVE-2026-84533: Vishal Patidar, Roman Zabicki

Heimdal
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: A user in a privileged network position may be able to leak
sensitive user information
Description: This is a vulnerability in open source code and Apple
Software is among the affected projects. The CVE-ID was assigned by a
third party. Learn more about the issue and CVE-ID at cve.org.
CVE-2022-3437: Roman Zabicki

HFS
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Mounting a maliciously crafted disk image may cause unexpected
system termination or corrupt kernel memory
Description: A buffer overflow was addressed with improved bounds
checking.
CVE-2026-84581: Feng Xue and XGPT of ThreatBook, Alfredo Pesoli (@__rev)
of Bynar.io, Jonathan Bar Or (@yo_yo_yo_jbo)

HFS
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Mounting a malicious disk image may cause unexpected system
termination
Description: A buffer overflow was addressed with improved bounds
checking.
CVE-2026-28934: Arni Hardarson (Neonix Security), Tristan Madani
(@TristanInSec) from Talence Security, 정우 하, Aswin Kumar Gokulakannan,
Peter Malone, Dun

iCloud
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to identify a user across reinstalls
Description: A privacy issue was addressed with improved handling of
identifiers.
CVE-2026-84606: Ilya Andr (andrd3v)

Image Capture
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access user-sensitive data
Description: A path handling issue was addressed with improved
validation.
CVE-2026-64756: Luke Symons

ImageIO
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing a maliciously crafted image may lead to a
denial-of-service
Description: A memory corruption issue was addressed with improved
bounds checking.
CVE-2026-64714: an anonymous researcher

ImageIO
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing a maliciously crafted image may result in disclosure
of process memory
Description: An uninitialized memory issue was addressed with improved
memory initialization.
CVE-2026-84564: Justin O'Leary

ImageIO
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing a maliciously crafted image may lead to unexpected
app termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-86869: Chris Bailey - Short Circuit, Meta Red Team X, Niels
Hofmans, Geonha Lee (@leegn4a)

ImageIO
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing a maliciously crafted image may result in memory
corruption
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-65395: Mateusz Jurczyk of Google Project Zero, Varik Matevosyan

IOKit
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause unexpected system termination
Description: A use after free issue was addressed with improved memory
management.
CVE-2026-28969: Mihalis Haatainen, Ashish Kunwar, Ari Hawking, 이재영

IOMobileFrameBuffer
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause unexpected system termination or
corrupt kernel memory
Description: An out-of-bounds access issue was addressed with improved
bounds checking.
CVE-2026-65398: Chris Bailey - Short Circuit, Mustafa Calap (@ordinal0,
dbg.re), David Strnadel, Meta Red Team X - Nik Tsytsarkin

IOSurfaceAccelerator
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to leak sensitive kernel state
Description: An information leakage was addressed with additional
validation.
CVE-2026-64760: an anonymous researcher, Seiji Sakurai (@HeapSmasher),
Franco Belman at Blackwing Intelligence

iWork
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: A malicious app may be able to break out of its sandbox
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-65354: Csaba Fitzl (@theevilbit) of Iru

Kernel
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Mounting a maliciously crafted disk image may cause unexpected
system termination or corrupt kernel memory
Description: A memory corruption issue was addressed by removing the
vulnerable code.
CVE-2026-84588: Narendra Singh (@_3P1C), Nathaniel Oh (@calysteon), an
anonymous researcher

Kernel
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause unexpected system termination or
corrupt kernel memory
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-28968: genter0, Svetoslav Stolarov & Aisa Fox, Josh Maine of
Calif.io, Dun

Kernel
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: A local attacker may be able to cause unexpected system
termination or corrupt kernel memory
Description: The issue was addressed with improved memory handling.
CVE-2026-84566: Bernhard Jackiewicz

Kernel
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: A local user may be able to cause unexpected system termination
or read kernel memory
Description: A race condition was addressed with additional validation.
CVE-2026-65415: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd., Ryan Hileman via Xint Code (xint.io)

Kernel
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause unexpected system termination or
corrupt kernel memory
Description: A double free issue was addressed with improved memory
management.
CVE-2026-84561: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd., Bhaswanth Chigurupati

Kernel
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause unexpected system termination
Description: A race condition was addressed with improved state
handling.
CVE-2026-84630: Tristan Madani (@TristanInSec) from Talence Security
CVE-2026-65401: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.
CVE-2026-65360: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.
CVE-2026-65358: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

Kernel
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause unexpected system termination
Description: A double free issue was addressed with improved memory
management.
CVE-2026-84558: James Young

Kernel
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause unexpected system termination
Description: A memory corruption issue was addressed with improved
memory handling.
CVE-2026-65377: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd., Ye Zhang (@VAR10CK) of Baidu Security

Kernel
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app with root privileges may be able to read uninitialized
kernel memory
Description: A memory initialization issue was addressed with improved
memory handling.
CVE-2026-84622: Hiroki Imai (LAC Co., Ltd.)

Kernel
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Connecting to a malicious NFS server may cause unexpected system
termination or corrupt kernel memory
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2026-84549: Aswin Kumar Gokulakannan, Surya Narayan Kushwaha

Kernel
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: A malicious app may be able to gain root privileges
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-43689: Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs

Kernel
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause unexpected system termination or
write kernel memory
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-84619: genter0, Eddy Tsalolikhin, James Duffy (@0x4A616D657344)

Kernel
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: A malicious application may bypass Gatekeeper checks
Description: A logic issue was addressed with improved state management.
CVE-2026-65369: an anonymous researcher

Kernel
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to gain root privileges
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-86917: Hiroki Imai (LAC Co., Ltd.)

Kernel
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Connecting to a malicious NFS server may cause unexpected system
termination or corrupt kernel memory
Description: An integer overflow was addressed with improved input
validation.
CVE-2026-84544: Abhijeet Singh (www.linkedin.com/in/abhiunix/), Surya
Narayan Kushwaha

Kernel
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: A remote attacker may be able to cause unexpected system
termination or corrupt kernel memory
Description: The issue was addressed with improved memory handling.
CVE-2026-43790: Omar Cerrito

Kernel
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Connecting to a malicious NFS server may disclose kernel memory
Description: The issue was addressed with improved memory handling.
CVE-2026-43687: R4mbb of KRsecurity, Peter Malone

Kernel
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Connecting to a malicious NFS server may lead to kernel memory
corruption
Description: A use-after-free issue was addressed with improved memory
management.
CVE-2026-43686: Peter Malone

Kernel
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: A remote attacker may be able to cause a denial-of-service
Description: A denial-of-service issue was addressed with improved input
validation.
CVE-2026-84538: Stuart Thomas

Kernel
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause unexpected system termination or
corrupt kernel memory
Description: A use-after-free issue was addressed with improved memory
management.
CVE-2026-43684: Peter Malone

Kernel
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to determine kernel memory layout
Description: A memory initialization issue was addressed with improved
memory handling.
CVE-2026-65405: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

Kernel
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: A remote attacker may be able to cause unexpected system
termination
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2026-65364: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

Kernel
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to disclose kernel memory
Description: An information disclosure issue was addressed with improved
memory management.
CVE-2026-84530: Vladislav Shevchenko (Positive Technologies)

Kernel
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause unexpected system termination
Description: A use after free issue was addressed with improved memory
management.
CVE-2026-84521: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.
CVE-2026-65402: Fábio Luís @scanpt, Richard Zana, Billy Jheng Bing Jhong
and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

Kernel
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: A local user may be able to cause unexpected system termination
or read kernel memory
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2026-65359: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

Kernel
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause unexpected system termination
Description: An integer overflow was addressed with improved input
validation.
CVE-2026-84517: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

Kernel
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause unexpected system termination or
corrupt kernel memory
Description: A race condition was addressed with improved state
handling.
CVE-2026-84507: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

Kernel
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to disclose kernel memory
Description: An out-of-bounds read was addressed with improved input
validation.
CVE-2026-86903: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

Kernel
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause unexpected system termination
Description: A type confusion issue was addressed with improved checks.
CVE-2026-84602: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

Kext Management
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to modify protected parts of the file system
Description: This issue was addressed with additional entitlement
checks.
CVE-2026-84514: Mohamed Wedatalla, Arjanit Isufi, Nathaniel Oh
(@calysteon)

Keychain Access
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved access
control.
CVE-2026-84556: Adrián Díaz Aguilar, Chris Bailey - Short Circuit, Peter
Malone, HvxyZLF

LaunchServices
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access sensitive user data
Description: A parsing issue in the handling of directory paths was
addressed with improved path validation.
CVE-2026-65382: an anonymous researcher

libarchive
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing a maliciously crafted file may lead to unexpected app
termination
Description: A heap buffer overflow was addressed with improved bounds
checking.
CVE-2026-86870: Kitten Food

libxpc
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to break out of its sandbox
Description: A logic issue was addressed with improved checks.
CVE-2026-86894: Dave G.

libxpc
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to bypass sandbox restrictions
Description: An access issue was addressed with additional sandbox
restrictions.
CVE-2026-84577: Dave G. and Alex Radocea of supernetworks.org

Mail
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access sensitive user data
Description: This issue was addressed with improved checks.
CVE-2026-84573: Dawuge of Shuffle Team

Mail
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An attacker in a privileged network position may be able to leak
sensitive user information
Description: A logic issue was addressed with improved checks.
CVE-2026-43787: Armend Gashi

MediaRemote
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: A sandboxed app may be able to access the System Keychain
Description: An authorization issue was addressed with improved state
management.
CVE-2026-84628: Myeonghun Pak, Nathaniel Oh (@calysteon), Alan Banderas
(@creeper4004)

Messages
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access protected user data
Description: A logic issue was addressed with improved state management.
CVE-2026-43741: Dawuge of Shuffle Team

MobileAccessoryUpdater
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Connecting a malicious accessory may cause unexpected system
termination
Description: A memory corruption issue was addressed with improved input
validation.
CVE-2026-86924: Matthew Zamat

Model I/O
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Opening a maliciously crafted file may lead to unexpected
process termination
Description: A buffer overflow was addressed with improved size
validation.
CVE-2026-84497: Yiğit Can YILMAZ (@yilmazcanyigit)

NetworkExtension
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access local network devices without user
consent
Description: A permissions issue was addressed with improved state
management.
CVE-2026-84585: Dmytro Merkulov

NetworkExtension
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state
management.
CVE-2026-43695: Claudio Bozzato and Francesco Benvenuto of Cisco Talos

NetworkExtension
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to identify what other apps a user has
installed
Description: An information disclosure issue was addressed with improved
state management.
CVE-2026-84626: Sindre Sorhus, Hoffcona of IES Red Team

NSDocument
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access sensitive user data
Description: A parsing issue in the handling of directory paths was
addressed with improved path validation.
CVE-2026-86902: silo

odproxyd
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to gain root privileges
Description: This issue was addressed with improved checks.
CVE-2026-64712: Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs

Photos Storage
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access sensitive user data
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-84491: an anonymous researcher

quarantine
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to break out of its sandbox
Description: The issue was addressed with improved checks.
CVE-2026-84580: an anonymous researcher

quarantine
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to break out of its sandbox
Description: A logic issue was addressed with improved checks.
CVE-2026-84578: Kenneth Chew

QuartzCore
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access sensitive user data
Description: This issue was addressed with improved checks.
CVE-2026-84576: Dora Orak, @Ethan Arbuckle, and @leptos_null

Quick Look
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing a maliciously crafted document may lead to an
out-of-bounds read
Description: An integer overflow was addressed with improved input
validation.
CVE-2026-84548: Peter Malone

RealityKit
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing a maliciously crafted file may lead to unexpected app
termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-28966: stratan (@5tratan)

RealityKit
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Opening a maliciously crafted file may cause unexpected process
termination or disclose process memory
Description: An out-of-bounds read issue was addressed with improved
input validation.
CVE-2026-84532: Hongsik Kim (mnur), stratan (@5tratan)

Reminders
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access sensitive user data
Description: This issue was addressed with improved checks.
CVE-2026-65403: Rahul Raj

Safari
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: A malicious website may be able to determine what apps a user
has installed
Description: This issue was addressed through improved state management.
CVE-2026-84518: Bálint Magyar (balintmagyar.com)

Safe Browsing
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access sensitive user data
Description: This issue was addressed with additional entitlement
checks.
CVE-2026-86897: Stuart Wallace

Sandbox
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access protected user data
Description: An issue existed in the handling of snapshots. The issue
was resolved with improved permissions logic.
CVE-2026-65380: Kieran Klukas (taciturnaxolotl)

Sandbox
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved access
control.
CVE-2026-84555: Liu Xue & 九宫格 of Chongqing Telecom

Sandbox
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to bypass network restrictions
Description: A logic issue was addressed with improved validation.
CVE-2026-84551: Issa Sancho

Sandbox Profiles
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to fingerprint the user
Description: A permissions issue was addressed with additional sandbox
restrictions.
CVE-2026-84625: Ilya Andr (andrd3v) of Positive Technologies, CJ Vana

SceneKit
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing a maliciously crafted 3D file may lead to an
out-of-bounds read
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2026-43697: Peter Malone

SceneKit
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing a maliciously crafted file may result in disclosure
of process memory
Description: An integer overflow was addressed with improved input
validation.
CVE-2026-84487: stratan (@5tratan), Dhiyanesh Selvaraj (@redroot97),
Peter Malone

SceneKit
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause a denial of service
Description: An integer overflow was addressed with improved input
validation.
CVE-2026-65413: Peter Malone

SceneKit
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing a maliciously crafted 3D model may lead to memory
corruption
Description: The issue was addressed with improved memory handling.
CVE-2026-84632: Peter Malone

SceneKit
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing a maliciously crafted 3D model may lead to memory
corruption
Description: An integer overflow was addressed with improved input
validation.
CVE-2026-84620: Peter Malone

SceneKit
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing a maliciously crafted 3D model may lead to memory
corruption
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-84546: Narendra Singh (@_3P1C), stratan (@5tratan), Peter
Malone
CVE-2026-84611: Nathaniel Oh (@calysteon)

SceneKit
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing a maliciously crafted 3D scene may lead to unexpected
process termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-84526: stratan (@5tratan)

Screen Sharing Server
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An attacker on the network may be able to authenticate to Screen
Sharing without valid credentials
Description: An authentication issue was addressed with improved state
management.
CVE-2026-65400: Alfredo Pesoli (@__rev) via Bynario Atlas (bynar.io)

Security
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An attacker in a privileged network position may be able to
intercept network traffic
Description: A certificate validation issue was addressed with improved
certificate validation.
CVE-2026-86889: Jaeho Nam, Jungbum Lee, Sangwi Kang, Hyeonguk Ko and
Taekyoung Kwon from SNU CSE MMLAB (mmlab.snu.ac.kr)

Security
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An attacker with a compromised intermediate certificate
authority may be able to issue certificates with arbitrary extended key
usages
Description: A certificate validation issue was addressed with improved
certificate validation.
CVE-2026-86881: Surya Narayan Kushwaha, Roman Zabicki, John Lussier,
Filip Olszak

Security
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing maliciously crafted NTLM input may lead to unexpected
app termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-84531: Meshaal (@unrealmesh)

Shortcuts
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: A malicious shortcut may be able to send messages without user
confirmation
Description: An authorization issue was addressed with improved state
management.
CVE-2026-84600: Owen Pawling (@owenpawling)

Siri
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access sensitive user data
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-86884: Stanislav Jelezoglo, Gongyu Ma (twitter @Mezone0)

SMB
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: A local user may be able to read kernel memory
Description: A race condition was addressed with improved locking.
CVE-2026-43690: Bruce Dang of Calif.io in collaboration with Claude and
Anthropic Research

SMB
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Mounting a maliciously crafted SMB network share may lead to
system termination
Description: A use-after-free issue was addressed with improved memory
management.
CVE-2026-43719: Jakob Pammer, Bruce Dang of Calif.io in collaboration
with Claude and Anthropic Research

SMB
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause unexpected system termination
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2026-65376: 재영 정, Bruce Dang of Calif.io in collaboration with
Claude and Anthropic Research

SMB
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Connecting to a malicious SMB server may cause unexpected system
termination or corrupt kernel memory
Description: An out-of-bounds access issue was addressed with improved
bounds checking.
CVE-2026-84543: Peter Malone

SMB
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause unexpected system termination or
corrupt kernel memory
Description: The issue was addressed with improved memory handling.
CVE-2026-84537: Feng Xue and XGPT of ThreatBook, Peter Malone

SMB
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Connecting to a malicious SMB server may lead to unexpected
system termination
Description: An integer underflow was addressed with improved input
validation.
CVE-2026-84536: 재영 정, Feng Xue and XGPT of ThreatBook, Peter Malone

SMB
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Connecting to a malicious SMB share may disclose kernel memory
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2026-65365: Jay Patel, Peter Malone

SMB
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Connecting to a malicious SMB server may lead to kernel memory
corruption
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-84515: 재영 정, Peter Malone

SMB
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Connecting to a malicious SMB server may lead to unexpected
system termination
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2026-84509: Dave G.

smbx
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: A remote attacker may be able to cause a denial-of-service
Description: A resource exhaustion issue was addressed with improved
input validation.
CVE-2026-84553: Stuart Thomas

Software Update
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to modify protected system files
Description: A permissions issue was addressed with improved path
validation.
CVE-2026-84609: YingMuo (@YingMuo) of DEVCORE Research Team

SoftwareUpdate
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access sensitive user data
Description: This issue was addressed with improved checks.
CVE-2026-65361: Rodolphe BRUNETTI (@eisw0lf) of Lupus Nova

Spotlight
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state
management.
CVE-2026-65378: Abodi Dawoud, Sindre Sorhus, 糖豆爸爸(@晴天组织), Niels Hofmans,
Robert Mindo

Spotlight
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved access
control.
CVE-2026-84621: Abodi Dawoud, Armend Gashi, Ujjwal Reddy Kalvolu
Sreenivasa Reddy, Johan Wahyudi

Spotlight
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing a maliciously crafted file may lead to a
denial-of-service or potentially disclose memory contents
Description: An integer overflow was addressed with improved input
validation.
CVE-2026-43788: Narendra Singh (@_3P1C), Ashish Kunwar

Storage
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to modify protected parts of the file system
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-65348: Jérôme Djouder

Storage
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access user-sensitive data
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-65345: Seung Je Seong, Ilya Andr (andrd3v) of Positive
Technologies, Jakob Pammer, 이재영

StorageKit
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to read arbitrary files
Description: A validation issue was addressed with improved input
sanitization.
CVE-2026-43791: Meridian Miftari, Amy (amys.website), Aaron Grattafiori
- - NVIDIA AI Red Team

Symptom Framework
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: A malicious application may be able to determine a user's
current location
Description: A privacy issue was addressed with improved private data
redaction for log entries.
CVE-2026-84513: Sindre Sorhus

System Settings
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may bypass Gatekeeper checks
Description: This issue was addressed with improved checks.
CVE-2026-65383: Zhongquan Li (@Guluisacat)

System Settings
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to bypass Gatekeeper checks
Description: A logic issue was addressed with improved state management.
CVE-2026-86909: Koh M. Nakagawa (@tsunek0h) of FFRI Security, Inc.

TCC
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access sensitive user data
Description: A logging issue was addressed with improved data redaction.
CVE-2026-84527: Zeyang Li&Yuxiang Wang of Chongqing Telecom

TCC
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to modify Privacy preferences
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-84589: an anonymous researcher, Rodolphe Brunetti (@eisw0lf),
Ryan Dowd (@_rdowd), Isaiah Ryan Ehlert (isaiahehlert () icloud com), Csaba
Fitzl (@theevilbit) of Iru

Terminal
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access sensitive user data
Description: This issue was addressed through improved state management.
CVE-2026-28937: Charlie Weiss, Noah Gregory (wts.dev)

Touch Bar
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to capture Touch Bar content without
authorization
Description: An authorization issue was addressed with improved
entitlement checks.
CVE-2026-43696: an anonymous researcher

udf
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause unexpected system termination or
read kernel memory
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2026-84572: Tomi (tk0) Koski (@tomikoski), Hari Shanmugam (The Hxr1)

udf
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to execute arbitrary code with kernel
privileges
Description: A use after free issue was addressed with improved memory
management.
CVE-2026-84506: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

WebDAV
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may bypass Gatekeeper checks
Description: A logic issue was addressed with improved checks.
CVE-2026-28899: Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs,
Kraken Cryptocurrency Exchange

WebDAV
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Connecting to a malicious WebDAV server may result in code
execution
Description: A memory corruption issue was addressed with improved
validation.
CVE-2026-65374: HE WEI(ギカク), Bruce Dang of Calif.io in collaboration
with Claude and Anthropic Research

WebDAV
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to cause unexpected system termination
Description: The issue was addressed with improved authentication.
CVE-2026-65375: YingMuo (@YingMuo) of DEVCORE Research Team, Bruce Dang
of Calif.io in collaboration with Claude and Anthropic Research

WebDAV
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Connecting to a malicious WebDAV server may lead to unexpected
app termination
Description: An out-of-bounds write issue was addressed by removing the
vulnerable code.
CVE-2026-43677: bubu, Omar Cerrito, HE WEI(ギカク), Roman Zabicki, Richard
Zana, Chris Bailey - Short Circuit, Aswin Kumar Gokulakannan, Surya
Narayan Kushwaha, Bruce Dang of Calif.io in collaboration with Claude
and Anthropic Research

WebKit
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing maliciously crafted web content may lead to an
unexpected process termination
Description: A logic issue was addressed with improved state management.
WebKit Bugzilla: 310457
CVE-2026-84635: Souta Sugiyama

WebKit
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing maliciously crafted web content may disclose
sensitive user information
Description: A permissions issue was addressed by removing the
vulnerable code.
WebKit Bugzilla: 315121
CVE-2026-64753: Viggo Lekdorf

WebKit
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Opening a maliciously crafted webarchive file may lead to
universal cross-site scripting
Description: A logic issue was addressed with improved state management.
WebKit Bugzilla: 3182711
CVE-2026-86898: Tomi Garcia (archyxsec)

WebKit Canvas
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: A use-after-free issue was addressed with improved memory
management.
WebKit Bugzilla: 313935
CVE-2026-64718: Niels Hofmans, OGINOME Tomohito, an anonymous researcher

Xcode IDE
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access user-sensitive data
Description: A permissions issue was addressed with improved validation.
CVE-2026-65393: Mickey Jin (@patch1t)

XPC
Available for: MacBook Neo (2026), MacBook Air with Apple silicon (2020
and later), MacBook Pro with Apple silicon (2020 and later), iMac with
Apple silicon (2021 and later), Mac mini with Apple silicon (2020 and
later), Mac Studio (2022 and later), and Mac Pro with Apple silicon
(2023)
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state
management.
CVE-2026-84617: Stuart Wallace

Additional recognition

Accounts
We would like to acknowledge Wojciech Regula of SecuRing
(wojciechregula.blog) for their assistance.

adv_cmds
We would like to acknowledge Franco Belman at Blackwing Intelligence for
their assistance.

AirPort
We would like to acknowledge Arni Hardarson (Neonix Security), Christian
Figueroa, Dhiyanesh Selvaraj (@redroot97), Harish Santhanalakshmi
Ganesan of Cisco AI Defense and a member of Cisco Talos, Niels Hofmans,
Robert Mindo, Tae Woo Kim (CYTUR) for their assistance.

APFS
We would like to acknowledge Nick Max, Ruslan Dautov for their
assistance.

App Intents
We would like to acknowledge Adetayo Adebimpe for their assistance.

Apple Account
We would like to acknowledge 糖豆爸爸(@晴天组织) for their assistance.

Apple Intelligence
We would like to acknowledge an anonymous researcher for their
assistance.

Apple Online Store Kit
We would like to acknowledge Pietro Francesco Tirenna (shielder.com),
Zhongcheng Li (CK01) for their assistance.

AppleEvents
We would like to acknowledge Noah Gregory (wts.dev) for their
assistance.

AppleKeyStore
We would like to acknowledge Abdurrahman Nafi, Francisco Knabe, Karol
Mazurek (@Karmaz95) of AFINE, Somair Ansar, YOKI, an anonymous
researcher, 晓娟 谢 for their assistance.

AVEVideoEncoder
We would like to acknowledge tamdao for their assistance.

Bluetooth
We would like to acknowledge David Maynor, Jason Grove, Suresh Sundaram,
Tae Woo Kim, jioundai for their assistance.

Calendar
We would like to acknowledge Dany Assuid, Jacob Hazak from Zero-Defense
Labs, Varik Matevosyan, stratan (@5tratan) for their assistance.

cd9660
We would like to acknowledge an anonymous researcher for their
assistance.

CipherML
We would like to acknowledge Nils Hanff (@[email protected]) of
Hasso Plattner Institute for their assistance.

CloudKit
We would like to acknowledge Hikerell (Loadshine Lab) for their
assistance.

Compression
We would like to acknowledge Nathaniel Oh (@calysteon) for their
assistance.

configd
We would like to acknowledge Mohammad Seet for their assistance.

copyfile
We would like to acknowledge Morris Richman (@morrisinlife) and Jian Lee
(@speedyfriend433) for their assistance.

CoreAudio
We would like to acknowledge Patrick Saif / x.com/weezerOSINT /
github.com/sai2fast for their assistance.

CoreBluetooth - LE
We would like to acknowledge Ashmit Sharma & Atul RV, Dun, Maliq
Barnard, Nicholas C. of Onymos Inc. (onymos.com), Peter Malone, Robert M
for their assistance.

CoreGraphics
We would like to acknowledge Gandalf4a of PKU-Changsha Institute for
Computing and Digital Economy for their assistance.

CoreMedia
We would like to acknowledge Chris Bailey - Short Circuit for their
assistance.

CoreSymbolication
We would like to acknowledge Maher Azzouzi for their assistance.

CoreText
We would like to acknowledge Jian Lee (@speedyfriend433) for their
assistance.

CoreUI
We would like to acknowledge Andrew Boni, Peter Malone for their
assistance.

CUPS
We would like to acknowledge Aaron Grattafiori - NVIDIA AI Red Team,
Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs, Katika
Mohaseen, Roman Zabicki, Sanny Mitra, Yongyue WANG AKA Brian.W of OKX
security, an anonymous researcher for their assistance.

DataAccess
We would like to acknowledge Adetayo Adebimpe (Cyboghostginx) for their
assistance.

Disk Images
We would like to acknowledge Noah Gregory (wts.dev), Peter Malone for
their assistance.

DiskArbitration
We would like to acknowledge Arni Hardarson (Neonix Security), FRO,
Mustafa Ahmed, Thomas Guillem, 九宫格 of Chongqing Telecom for their
assistance.

dyld
We would like to acknowledge Krishna Agarwal (Kr1shna4garwal) for their
assistance.

FaceTime
We would like to acknowledge Souhaib Naceri for their assistance.

Family Sharing
We would like to acknowledge Robert Mindo for their assistance.

Files
We would like to acknowledge an anonymous researcher for their
assistance.

Finder
We would like to acknowledge Brian McNulty, Michael Telloyan for their
assistance.

Heimdal
We would like to acknowledge Roman Zabicki for their assistance.

HFS
We would like to acknowledge Anton Pakhunov, an anonymous researcher for
their assistance.

iCloud
We would like to acknowledge 3ndy1(@_3ndy1) and moyu, Gabriel Rodrigues
from Hakai, l3lue for their assistance.

Identity Services
We would like to acknowledge Ismael Esquilichi and Pablo Redondo
(cmdresearch) for their assistance.

ImageIO
We would like to acknowledge Muhamad Syaiful, an anonymous researcher,
songbird for their assistance.

Installer
We would like to acknowledge John Woodman, Mahmoud Abdelmoniem, Meridian
Miftari, Niels Hofmans, an anonymous researcher for their assistance.

IOMobileFrameBuffer
We would like to acknowledge Iain Harkiss, Jian Lee (@speedyfriend433)
for their assistance.

IOSurfaceAccelerator
We would like to acknowledge Chanwit Muenprakoddee (ChemIndy), Franco
Belman at Blackwing Intelligence, Iain Harkiss, an anonymous researcher,
beist, hxr1 for their assistance.

Kernel
We would like to acknowledge Ahmed Alwardani, Aswin Kumar Gokula Kannan,
Bhaswanth Chigurupati, Billy Jheng Bing Jhong and Pan Zhenpeng
(@Peterpan0927) of STAR Labs SG Pte. Ltd., Cem Onat Karagun, DARKNAVY
(@DarkNavyOrg), Gil Portnoy & Henry, James Duffy (@0x4A616D657344), Kang
Sangkwun, Lyutoon, N.M.Praveen Nawarathne (@zblockrat), Nebula Security
(@nebusecurity), Nicolas Seriot, Peter Malone, Redon Gashi of Sentry,
Robert Tran, Suresh Sundaram, Tristan Madani (@TristanInSec) from
Talence Security, Xiang Li from AOSP Lab @Nankai University, an
anonymous researcher for their assistance.

libarchive
We would like to acknowledge Roman Zabicki, Surya Narayan Kushwaha,
Paulos Yibelo, Sidharth Rajalakshmi for their assistance.

libxpc
We would like to acknowledge Fábio Luís (@scanpt), an anonymous
researcher for their assistance.

Local Authentication
We would like to acknowledge Ashish Kunwar for their assistance.

LoginWindow
We would like to acknowledge Thomas Guillem for their assistance.

mDNSResponder
We would like to acknowledge Anton Pakhunov, Franciszek Kalinowski
(striga.ai / isec.pl), Hannes Weissteiner, Roland Czerny, Simone Franza,
Stefan Gast and Daniel Gruss of Graz University of Technology, and
Johanna Ullrich of the Interdisciplinary Transformation University
(IT:U), Issa Sancho, Jian Zhou, 章鱼哥@aipy (aipyaipy.com) for their
assistance.

ncurses
We would like to acknowledge Yashashree Gund for their assistance.

Notifications
We would like to acknowledge Abhay Kailasia (@abhay_kailasia) from
Safran Mumbai India, Himanshu Bharti @Xpl0itme From Khatima, Jan Rokita
(rokita.me) for their assistance.

PaperKit
We would like to acknowledge Rahul Raj for their assistance.

Passwords
We would like to acknowledge Catalin Lita of Moralis, Christian
Kohlschütter, David Coomber of Info-Sec.CA, Lukasz Tulikowski at
Software Cloud, Sujay Amin, an anonymous researcher for their
assistance.

ppp
We would like to acknowledge Cem Onat Karagun for their assistance.

Pro Res
We would like to acknowledge Meta Red Team X - Nik Tsytsarkin for their
assistance.

quarantine
We would like to acknowledge an anonymous researcher for their
assistance.

Quick Look
We would like to acknowledge Peter Malone for their assistance.

RemoteServiceDiscovery
We would like to acknowledge Tristan Madani (@TristanInSec) from Talence
Security, an anonymous researcher for their assistance.

Safari
We would like to acknowledge Dem0ns @天府简易信工作室 for their assistance.

Safari Downloads
We would like to acknowledge Barath Stalin K
(linkedin.com/in/barathstalin), Exell Nakano, Manojkumar Jaganathan
(linkedin.com/in/manojkumar-j-7ba35b202/) with HackerBro Technologies,
Praditya Fajar Ramadhan, Zhiyang Zeng (@Wester), shobhit srivastav for
their assistance.

Sandbox
We would like to acknowledge Asaf Cohen for their assistance.

Screen Sharing
We would like to acknowledge Asaf Cohen for their assistance.

Security
We would like to acknowledge Feng Xue and XGPT of ThreatBook, John
Lussier, Masahiro Kawada (@kawakatz), Roman Zabicki, kem0n for their
assistance.

Share Sheet
We would like to acknowledge Atul Kishor Jaiswal, Benjamin Hornbeck for
their assistance.

Shortcuts
We would like to acknowledge Csaba Fitzl (@theevilbit) of Iru, Owen
Pawling (@owenpawling) for their assistance.

SMB
We would like to acknowledge Omar Cerrito, Peter Malone for their
assistance.

Terminal
We would like to acknowledge Stuart Thomas for their assistance.

Virtualization
We would like to acknowledge Ye Zhang (@VAR10CK) of Baidu Security for
their assistance.

VoiceOver
We would like to acknowledge Hariji Vivek Pandey for their assistance.

WebDAV
We would like to acknowledge Bruce Dang of Calif.io in collaboration
with Claude and Anthropic Research, YingMuo (@YingMuo) of DEVCORE
Research Team for their assistance.

WebKit
We would like to acknowledge @TristanInSec, Behzad Najjarpour Jabbari
(@_G4ru_), Big Bear, Eddy Tsalolikhin, Henock Habte, Kenneth Hsu, Maher
Azzouzi, Meridian Miftari, N13S, OpenAI Codex Security - Amy Burnett,
Souta Sugiyama, Vitaly Simonovich, an anonymous researcher,
hamayanhamayan, lattice, lebr0nli of National Yang Ming Chiao Tung
University, Security and Systems Lab, ret2happy, wwwlk for their
assistance.

WebKit Canvas
We would like to acknowledge Utkarsh Pal for their assistance.

WebKit JavaScript Bindings
We would like to acknowledge hamayanhamayan for their assistance.

WindowServer
We would like to acknowledge Jex Amro for their assistance.

xar
We would like to acknowledge Matthew Dean for their assistance.

macOS Golden Gate 27 may be obtained from the Mac App Store or Apple's
Software Downloads web site: https://support.apple.com/downloads/

All information is also posted on the Apple Security Releases
web site: https://support.apple.com/100100.

This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEhjkl+zMLNwFiCT1o4Ifiq8DH7PUFAmqoYkQACgkQ4Ifiq8DH
7PVkUQ//fQX25FQzU0VT65TiXewV7Aw7yl7Bbe3V+qEtvOHm/35uyzlm6WKr2cu1
YFEd88hBfFXlsFcATZKNmdZk78T/G6ys0d9ugcwRWcUHvPgiW0e1w7+2wAQJ6Qx1
uikuWmuy6uEls+2VxMsCVFsPUfNUt5bXI3h3rN2VldNgts1sh8gfeTJjypYOKukl
VEpVlj4G14CudrCUlXivJ0etGzYhW4QwHfEoppsuhFpgqqnlI9KcYhg84RElJAV9
+S1/2+OB84znqUKksJN0WoQb4B1g5mv8qqm3O0jzXXBJldlq/FEV8xSZIPmBiQAt
a2SaBOmvUUyvjJThlNBQ04DMK3S5TY46fA2+dfAVXcNJORnyrKzCOs+txvssAF1n
aPlJisiOj9ALyzZ4pU+aW3DJ1RGst5WH7oUQ52riRGJr9dO3MGmBlwX5rm3WE5DQ
wBF+54VE4EDIWM8IEQqC6b1t3SZ+A6BaiXSLZ2dj0ebILBMqqQpX6loZwGHYaCig
SbTsrLca1lqOyCJzeD8dcF/TwyPP5XDjsZgKHI5MR9aSwAWqg/d9zdqoCiUvxOiP
+d4rK9xNmhqFnG9RXu+i+r+ngYn0URnq76zQlUp6NDgVri2T69KaoNTdQUmjR3k0
CvGfzk2n30dEUXgrtujwE/G4l3BT4tAyVqvdb7fzaSvXWrbdFM0=
=3wK2
-----END PGP SIGNATURE-----

_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/

Current thread:

  • APPLE-SA-09-14-2026-3 macOS Golden Gate 27 Apple Product Security via Fulldisclosure (Sep 22)

文章来源: https://seclists.org/fulldisclosure/2026/Sep/55
如有侵权请联系:admin#unsafe.sh