CVE Feed

    Dashboard / CVE

    6.9
    Medium

    CVE-2026-66825

    Last Modified: 28 Jul 2026

    Pivotick contains a cross-site scripting vulnerability in the sidebar property-list component. Values associated with link-like properties, such as url, uri, href, link, website, or homepage, were rendered as hyperlinks without validating their URL scheme. An attacker able to supply or influence node or edge property data could provide a malicious value using the javascript: scheme, including variants obfuscated with whitespace or control characters. If a user clicked the generated property link, attacker-controlled JavaScript could execute in the context of the Pivotick application. Successful exploitation could allow the attacker to access information available to the victim’s browser session or perform actions with the victim’s privileges. The vulnerability was addressed by normalizing property values and preventing URLs with non-allowlisted schemes from being rendered as clickable links.

    Published: 27 Jul 2026
    9.8
    Critical

    CVE-2026-43757

    Last Modified: 17 Aug 2026

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

    Published: 27 Jul 2026
    8.2
    High

    CVE-2026-64737

    Last Modified: 4 Aug 2026

    An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox.

    Published: 27 Jul 2026
    5.5
    Medium

    CVE-2026-43782

    Last Modified: 4 Aug 2026

    This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access sensitive user data.

    Published: 27 Jul 2026
    9.8
    Critical

    CVE-2026-43805

    Last Modified: 3 Aug 2026

    A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.

    Published: 27 Jul 2026
    9.8
    Critical

    CVE-2026-39873

    Last Modified: 5 Aug 2026

    The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Connecting to a malicious SMB server may lead to unexpected system termination.

    Published: 27 Jul 2026
    5.5
    Medium

    CVE-2026-64776

    Last Modified: 4 Aug 2026

    The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to disclose kernel memory.

    Published: 27 Jul 2026
    7.1
    High

    CVE-2026-43813

    Last Modified: 5 Aug 2026

    A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A maliciously crafted app may be able to bypass code signing enforcement.

    Published: 27 Jul 2026
    5.5
    Medium

    CVE-2026-64721

    Last Modified: 17 Aug 2026

    This issue was addressed through improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.

    Published: 27 Jul 2026
    5.5
    Medium

    CVE-2026-20672

    Last Modified: 22 Aug 2026

    An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.3. An app may be able to access sensitive user data.

    Published: 27 Jul 2026
    9.3
    Critical

    CVE-2026-64740

    Last Modified: 17 Aug 2026

    A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6. A malicious app may be able to break out of its sandbox.

    Published: 27 Jul 2026
    9.8
    Critical

    CVE-2026-64691

    Last Modified: 3 Aug 2026

    A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

    Published: 27 Jul 2026
    7.8
    High

    CVE-2026-43673

    Last Modified: 17 Aug 2026

    The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted audio file may corrupt process memory.

    Published: 27 Jul 2026
    8.8
    High

    CVE-2026-64783

    Last Modified: 20 Aug 2026

    A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.

    Published: 27 Jul 2026
    9.8
    Critical

    CVE-2026-43809

    Last Modified: 17 Aug 2026

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

    Published: 27 Jul 2026
    5.5
    Medium

    CVE-2026-43665

    Last Modified: 4 Aug 2026

    This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A local attacker may be able to determine the legacy VNC password configured for Screen Sharing.

    Published: 27 Jul 2026
    7.5
    High

    CVE-2026-43777

    Last Modified: 4 Aug 2026

    This issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote attacker may be able to cause a denial of service.

    Published: 27 Jul 2026
    9.8
    Critical

    CVE-2026-43799

    Last Modified: 17 Aug 2026

    A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

    Published: 27 Jul 2026
    7.8
    High

    CVE-2026-43776

    Last Modified: 18 Aug 2026

    A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

    Published: 27 Jul 2026
    5.5
    Medium

    CVE-2026-28900

    Last Modified: 26 Aug 2026

    A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. A maliciously crafted ZIP archive may bypass Gatekeeper checks.

    Published: 27 Jul 2026
    7.1
    High

    CVE-2026-43672

    Last Modified: 4 Aug 2026

    An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious application may be able to bypass Privacy preferences.

    Published: 27 Jul 2026
    8.6
    High

    CVE-2026-43760

    Last Modified: 3 Aug 2026

    An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access user-sensitive data.

    Published: 27 Jul 2026
    5.5
    Medium

    CVE-2026-64741

    Last Modified: 5 Aug 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and iPadOS 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to read a persistent device identifier.

    Published: 27 Jul 2026
    7.8
    High

    CVE-2026-64716

    Last Modified: 18 Aug 2026

    The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted image may corrupt process memory.

    Published: 27 Jul 2026
    9.8
    Critical

    CVE-2026-28982

    Last Modified: 4 Aug 2026

    A race condition was addressed with improved locking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.

    Published: 27 Jul 2026
    9.8
    Critical

    CVE-2026-64700

    Last Modified: 18 Aug 2026

    A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

    Published: 27 Jul 2026
    8.8
    High

    CVE-2026-64757

    Last Modified: 20 Aug 2026

    A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.

    Published: 27 Jul 2026
    9.8
    Critical

    CVE-2026-64720

    Last Modified: 4 Aug 2026

    A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

    Published: 27 Jul 2026
    5.5
    Medium

    CVE-2026-28849

    Last Modified: 26 Aug 2026

    The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. A maliciously crafted ZIP archive may bypass Gatekeeper checks.

    Published: 27 Jul 2026
    9.8
    Critical

    CVE-2026-43812

    Last Modified: 17 Aug 2026

    A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. An app may be able to cause unexpected system termination.

    Published: 27 Jul 2026
    6.5
    Medium

    CVE-2026-43804

    Last Modified: 20 Aug 2026

    This issue was addressed through improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6. Visiting a website may lead to an app denial-of-service.

    Published: 27 Jul 2026
    5.5
    Medium

    CVE-2026-43756

    Last Modified: 3 Aug 2026

    A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access user-sensitive data.

    Published: 27 Jul 2026
    5.5
    Medium

    CVE-2026-64707

    Last Modified: 18 Aug 2026

    A permissions issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, visionOS 26.6. An app may be able to delete files for which it does not have permission.

    Published: 27 Jul 2026
    5.5
    Medium

    CVE-2026-64711

    Last Modified: 4 Aug 2026

    This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to leak sensitive user information.

    Published: 27 Jul 2026
    9.8
    Critical

    CVE-2026-64746

    Last Modified: 18 Aug 2026

    An authorization issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. An app may be able to add contacts without user authorization.

    Published: 27 Jul 2026
    5
    Medium

    CVE-2026-43767

    Last Modified: 5 Aug 2026

    The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

    Published: 27 Jul 2026
    9.8
    Critical

    CVE-2026-64697

    Last Modified: 13 Aug 2026

    The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.

    Published: 27 Jul 2026
    9.8
    Critical

    CVE-2026-43730

    Last Modified: 4 Aug 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to fingerprint the user.

    Published: 27 Jul 2026
    9.8
    Critical

    CVE-2026-28911

    Last Modified: 4 Aug 2026

    The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to corrupt memory of a system process.

    Published: 27 Jul 2026
    5.5
    Medium

    CVE-2026-43819

    Last Modified: 4 Aug 2026

    An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.6. An app may be able to access sensitive user data.

    Published: 27 Jul 2026
    7.1
    High

    CVE-2026-43771

    Last Modified: 13 Aug 2026

    A stack overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause a denial-of-service.

    Published: 27 Jul 2026
    7.1
    High

    CVE-2026-43747

    Last Modified: 4 Aug 2026

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Parsing a maliciously crafted file may lead to an unexpected app termination.

    Published: 27 Jul 2026
    8.8
    High

    CVE-2026-28931

    Last Modified: 3 Aug 2026

    A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. Connecting to a malicious NFS server may lead to kernel memory corruption.

    Published: 27 Jul 2026
    9.8
    Critical

    CVE-2026-43710

    Last Modified: 5 Aug 2026

    The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An attacker may be able to cause unexpected system termination or corrupt kernel memory.

    Published: 27 Jul 2026
    9.8
    Critical

    CVE-2026-64731

    Last Modified: 4 Aug 2026

    A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox.

    Published: 27 Jul 2026
    7.8
    High

    CVE-2026-64766

    Last Modified: 17 Aug 2026

    An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

    Published: 27 Jul 2026
    9.8
    Critical

    CVE-2026-43803

    Last Modified: 17 Aug 2026

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote attacker may be able to cause unexpected system termination.

    Published: 27 Jul 2026
    7.8
    High

    CVE-2026-39875

    Last Modified: 3 Aug 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.

    Published: 27 Jul 2026
    9.8
    Critical

    CVE-2026-64770

    Last Modified: 17 Aug 2026

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.

    Published: 27 Jul 2026
    9.8
    Critical

    CVE-2026-64727

    Last Modified: 13 Aug 2026

    A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26.6, tvOS 26.6. An app may be able to cause unexpected system termination.

    Published: 27 Jul 2026