Apple macOS

296 known vulnerabilities in Apple macOS, 17 critical, 72 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2026-86950 CVSS 8.8 high · actively exploited Apple Multiple Products Out-of-Bounds Write Vulnerability
  • CVE-2026-65400 CVSS 9.8 critical · actively exploited Apple macOS Improper Authentication Vulnerability
  • CVE-2026-20700 CVSS 7.8 high · actively exploited Apple Multiple Buffer Overflow Vulnerability
  • CVE-2025-43529 CVSS 8.8 high · actively exploited Apple Multiple Products Use-After-Free WebKit Vulnerability
  • CVE-2025-43520 CVSS 5.5 medium · actively exploited Apple Multiple Products Classic Buffer Overflow Vulnerability
  • CVE-2025-43510 CVSS 7.8 high · actively exploited Apple Multiple Products Improper Locking Vulnerability
  • CVE-2023-43000 CVSS 8.8 high · actively exploited Apple Multiple products Use-After-Free Vulnerability
  • CVE-2025-43300 CVSS 10.0 critical · actively exploited Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability
  • CVE-2025-31277 CVSS 8.8 high · actively exploited Apple Multiple Products Buffer Overflow Vulnerability
  • CVE-2025-43200 CVSS 4.2 medium · actively exploited Apple Multiple Products Unspecified Vulnerability

Latest vulnerabilities

  • CVE-2026-86950 CVSS 8.8 high · actively exploited Apple Multiple Products Out-of-Bounds Write Vulnerability
  • CVE-2026-86924 CVSS 5.5 medium A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS…
  • CVE-2026-86917 CVSS 7.8 high A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS…
  • CVE-2026-86911 CVSS 5.5 medium This issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. A malicious app may be able to…
  • CVE-2026-86910 CVSS 5.5 medium A permissions issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS…
  • CVE-2026-86909 CVSS 4.4 medium A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to bypass…
  • CVE-2026-86905 CVSS 5.5 medium This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27…
  • CVE-2026-86903 CVSS 5.5 medium An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27…
  • CVE-2026-86902 CVSS 5.5 medium A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Golden Gate…
  • CVE-2026-86901 CVSS 7.1 high An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27. Mounting a…
  • CVE-2026-86900 CVSS 6.5 medium An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27. Mounting a…
  • CVE-2026-86898 CVSS 5.4 medium A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27…
  • CVE-2026-86897 CVSS 5.5 medium This issue was addressed with additional entitlement checks. This issue is fixed in Safari 27, iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS…
  • CVE-2026-86894 CVSS 7.5 high A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27. An app may be able to break out of its…
  • CVE-2026-86891 CVSS 3.5 low An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8…
  • CVE-2026-86889 CVSS 4.8 medium A certificate validation issue was addressed with improved certificate validation. This issue is fixed in macOS Golden Gate 27, macOS…
  • CVE-2026-86888 CVSS 3.3 low A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS…
  • CVE-2026-86884 CVSS 5.5 medium A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS…
  • CVE-2026-86882 CVSS 6.5 medium An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and…
  • CVE-2026-86881 CVSS 9.1 critical A certificate validation issue was addressed with improved certificate validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27…
  • CVE-2026-86876 CVSS 5.2 medium An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and…
  • CVE-2026-86870 CVSS 6.5 medium A heap buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27…
  • CVE-2026-86869 CVSS 6.5 medium An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, macOS Golden…
  • CVE-2026-84635 CVSS 6.5 medium A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27…
  • CVE-2026-84632 CVSS 7.3 high The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden…
  • CVE-2026-84631 CVSS 7.8 high This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27. An app may be able to gain root…
  • CVE-2026-84630 CVSS 4.7 medium A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS…
  • CVE-2026-84628 CVSS 5.5 medium An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27…
  • CVE-2026-84626 CVSS 3.3 low An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and…
  • CVE-2026-84625 CVSS 9.1 critical A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27…