These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
An authentication issue was addressed with improved state management in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, and macOS Tahoe 26.6.1. This issue could allow an attacker on the network to authenticate to Screen Sharing without valid credentials. Organizations and individuals using these macOS versions should be aware of the potential risks and take steps to patch their systems. The CVE record was publ [truncated]
A permissions issue was addressed with additional restrictions in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6. This issue could allow a malicious app to gain root privileges if exploited. The CVE record was published on 2026-07-27T21:16:51.533Z and has not been modified since then. Users and administrators of macOS Sequoia, Sonoma, and Tahoe should apply the recommended patches to prev [truncated]
Apple has addressed an out-of-bounds write issue in Safari, which could lead to an unexpected browser crash when processing maliciously crafted web content. The issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6. This vulnerability has a CVSS score of 6.5 and a severity of MEDIUM.
A race condition vulnerability was addressed with improved state handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination. The vulnerability is a race condition issue that affects various Apple operating systems. The CVSS score for this vulnerability is 4.7, indicating a medium severity level.
A use-after-free issue was addressed with improved memory management in Safari. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. The vulnerability could lead to an unexpected process crash when processing maliciously crafted web content. Users of Apple products, particularly those using Safari, should apply the latest security [truncated]
Apple has addressed a memory handling issue in multiple products, including Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The issue was fixed in various versions, including Safari 26.5.2 and 26.6, iOS 26.5.2 and 26.6, iPadOS 26.5.2 and 26.6, macOS Tahoe 26.5.2 and 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6. This vulnerability could lead to the disclosure of process memory when processing [truncated]
A vulnerability was addressed with improved checks in Apple products. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may exfiltrate data cross-origin. The vulnerability has a CVSS score of 8.1, indicating a HIGH severity level. Users of Apple products, particularly those using Safari, iOS, iPadOS, macOS, t [truncated]
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. The vulnerability involves a use-after-free issue that could lead to an unexpected process crash when processing maliciously crafted web content. Apple has released updates for Safari, iOS, iPadOS, macOS, tvOS, [truncated]
CVE-2026-43732 is a path handling issue addressed with improved validation in various Apple products, including Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6. The issue is related to the handling of maliciously crafted web content, which may disclose sensitive user information. Users of these products should apply the latest security updates to [truncated]
A use-after-free issue was addressed with improved memory management in Safari and multiple Apple operating systems, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The issue may lead to memory corruption when processing maliciously crafted web content. This vulnerability has been fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26. [truncated]
A use-after-free issue was addressed with improved memory management in Apple Safari and other affected products. This issue could lead to an unexpected Safari crash when processing maliciously crafted web content. The vulnerability affects various Apple platforms, including Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, visionOS 26.6, and watchOS 26.6. The issue requires user interactio [truncated]
A use-after-free issue was addressed with improved memory management in various Apple products, including Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. This vulnerability could lead to an unexpected process crash when processing maliciously crafted web content. The issue has been mitigated through updates provided by Apple. The vulnerability's impact is primarily related to service disruption t [truncated]
A malicious website may be able to process restricted web content outside the sandbox due to improper input validation in various Apple products. This issue was addressed with improved input validation and is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. The vulnerability has a CVSS score of 7.1, indicating high severity. Users of Apple p [truncated]
CVE-2026-43724 is an input sanitization issue affecting multiple Apple products, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The issue was addressed with improved input sanitization and is fixed in various versions of these operating systems. This vulnerability allows an app to potentially cause unexpected system termination or write kernel memory. Users of Apple devices should apply availa [truncated]
A vulnerability, CVE-2026-43722, was addressed by Apple through improved input sanitization. This issue affected various Apple operating systems, including iOS, iPadOS, and macOS. An application may have been able to leak sensitive kernel state due to this vulnerability. Apple has released updates to fix this issue, which are iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and mac [truncated]
A stack overflow vulnerability was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. The vulnerability can be triggered by processing maliciously crafted web content, potentially leading to an unexpected Safari crash. Users of affected Apple products should apply the latest security upda [truncated]
A use-after-free issue was addressed with improved memory management in Safari. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, watchOS 26.6. The vulnerability could lead to an unexpected Safari crash when processing maliciously crafted web content. Users of affected products should apply updates to prevent potential crashes.
A use-after-free issue was addressed with improved memory management in multiple Apple operating systems and Safari. This vulnerability, CVE-2026-43715, could potentially lead to memory corruption when processing maliciously crafted web content. Users of Apple products, particularly those using Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS, should apply the latest security updates to prevent pot [truncated]
A permissions issue was addressed with additional restrictions in various Apple products, including Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The issue allows sensitive data to potentially leak when visiting a website. Apple has addressed this issue with additional restrictions in the specified security updates. Users of Apple products should apply the latest security updates to prevent pot [truncated]
Apple has addressed a vulnerability in multiple products that could lead to an unexpected process crash when processing maliciously crafted web content. This issue was fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. The vulnerability is related to improved memory handling. Users of Apple products, particularly those who use Safari, iOS, iPa [truncated]
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. The vulnerability can lead to an unexpected process crash when processing maliciously crafted web content. Users of Apple products should apply the latest security updates to prevent potential crashes.
A malicious website may exfiltrate data cross-origin due to an input validation issue addressed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. This issue has a CVSS score of 4.3 and is considered Medium severity. The vulnerability allows a malicious website to potentially exfiltrate data cross-origin.
A memory corruption issue was addressed with improved memory handling in Apple products. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. The vulnerability involves a memory corruption issue that could lead to an unexpected process crash when processing maliciously crafted web content. Users should apply the latest security upd [truncated]
A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. The vulnerability could lead to an unexpected process crash when processing maliciously crafted web content. This issue has a medium severity with a CVSS score of 6.5. Users of Apple de [truncated]
A type confusion issue was addressed with improved checks in various Apple products, including Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. This issue could lead to memory corruption when processing maliciously crafted web content. The vulnerability's impact is considered High, with a CVSS score of 8.8. Users of Apple products should apply the latest security updates to prevent potential memor [truncated]
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. A malicious web extension may be able to cause an unexpected process crash. Users of Apple products, particularly those using Safa [truncated]
Apple has addressed a memory handling issue in multiple products, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The issue could lead to an unexpected process crash when processing maliciously crafted web content. This vulnerability, tracked as CVE-2026-43703, has a CVSS score of 6.5, indicating a medium severity level. The affected products include iOS, iPadOS, macOS Sequoia, macOS Sonoma, ma [truncated]
Apple has addressed a vulnerability in multiple products, including Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The issue was addressed with improved checks, fixing a problem where a malicious website may be able to process restricted web content outside the sandbox. This vulnerability has a high severity with a CVSS score of 7.1. Users of affected products should apply security updates immed [truncated]
CVE-2026-43700 is a cross-origin issue affecting various Apple products, including Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The issue was addressed with improved tracking of security origins. This vulnerability has a CVSS score of 6.5 and can lead to disclosure of sensitive user information if exploited. Users of affected Apple products should apply available updates to prevent potential d [truncated]
A use-after-free issue was addressed with improved memory management in Apple Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. This issue can lead to an unexpected process crash when processing maliciously crafted web content. The vulnerability affects users of Apple products and has been addressed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6.
Apple has addressed a memory handling issue in multiple products, including Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6. The issue could lead to an unexpected process crash when processing maliciously crafted web content. This vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity. Users of Apple products, particularly tho [truncated]
Apple has addressed a memory handling issue in multiple products, including Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6. The issue could lead to an unexpected process crash when processing maliciously crafted web content. This vulnerability is classified as a denial-of-service (DoS) issue, which could potentially be used to cause service disr [truncated]
A critical vulnerability, CVE-2026-39868, was addressed by Apple through improved input validation. This issue affects multiple Apple operating systems, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. An application may exploit this vulnerability to cause unexpected system termination or corrupt kernel memory. The vulnerability has a CVSS score of 9.1 and is considered critical. Organizations a [truncated]
CVE-2025-46315 is a HIGH-severity vulnerability (CVSS Score: 7.5) affecting macOS, which was publicly disclosed on 2026-06-11. The issue involves a permissions problem that was resolved with additional restrictions in macOS Tahoe 26.1. Successful exploitation could allow an app to access protected user data. Apple has provided a vendor advisory [ref-4] detailing the fix.
CVE-2025-46313 is a medium-severity vulnerability (CVSS Score: 5.5) that was publicly disclosed on 2026-06-11T19:16:34.603Z and last modified on 2026-06-12T22:16:47.890Z. The vulnerability is related to a logging issue that was addressed with improved data redaction in macOS Tahoe 26.1. According to the CVE description, an app may be able to access sensitive user data due to this issue. The CVE record can [truncated]
CVE-2025-46308 is a medium-severity vulnerability (CVSS Score: 5.3) affecting iOS, iPadOS, and macOS. An authorization issue was addressed with improved state management, fixing a bug that allowed an app to leak sensitive user information. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4.
CVE-2025-46293 is a medium-severity vulnerability in Apple macOS, addressed in macOS Sequoia 15.4. The issue was related to improved handling of symlinks. An app may be able to access protected user data. The CVSS score for this vulnerability is 5.5.
CVE-2025-43339 is a MEDIUM-severity access issue vulnerability addressed by Apple in macOS Tahoe 26.1. A malicious app may be able to access sensitive user data. The issue was publicly disclosed on [**cve-org**](https://www.cve.org/CVERecord?id=CVE-2025-43339) and further details can be found on [**nvd**](https://nvd.nist.gov/vuln/detail/CVE-2025-43339).
CVE-2025-43278 is a medium-severity vulnerability (CVSS Score: 5.5) that was addressed with improved handling of symlinks. The issue is fixed in macOS Sequoia 15.4. According to the CVE description, an app may be able to access protected user data. The CVE was published on [cvePublishedAt] and modified on [cveModifiedAt].
CVE-2025-31272 is a HIGH severity vulnerability in macOS Sequoia 15.4. The issue was addressed with improved checks. An app may be able to bypass launch constraint protections and execute malicious code with elevated privileges. The CVSS score for this vulnerability is 7.8.
CVE-2025-30459 is a medium-severity privacy issue in Apple macOS Sequoia 15.4. The vulnerability allowed an app to potentially access sensitive user data due to the presence of vulnerable code, which has since been removed. This issue was publicly disclosed on [cvePublishedAt] and last modified on [cveModifiedAt].
CVE-2025-30431 is a medium-severity vulnerability in Apple macOS, allowing malicious apps to access private information. The issue was addressed with improved checks and is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, and macOS Ventura 13.7.5.
CVE-2025-24284 is a HIGH severity vulnerability in Apple macOS, with a CVSS score of 8.8. The issue was addressed with improved checks to prevent unauthorized actions and is fixed in macOS Sequoia 15.4. An app may be able to break out of its sandbox due to this vulnerability.
CVE-2025-24268 is a medium-severity vulnerability (CVSS Score: 5.5) affecting macOS Sequoia. The issue involves a parsing problem with directory paths that was resolved through improved path validation, fixed in macOS Sequoia 15.4. Successful exploitation could allow an app to access sensitive user data.
CVE-2025-24165 is a medium-severity vulnerability (CVSS Score: 5.5) affecting macOS. An app may be able to cause unexpected system termination due to a permissions issue, which was addressed with additional restrictions in macOS Sequoia 15.4, macOS Sonoma 14.7.5, and macOS Ventura 13.7.5.
CVE-2022-48575 is a low-severity vulnerability (CVSS Score: 3.5) affecting macOS Monterey. A person with access to a Mac may be able to bypass Login Window due to a consistency issue addressed with improved state handling. This issue was fixed in macOS Monterey 12.4.
CVE-2022-26758 is a HIGH severity vulnerability in Apple macOS Monterey versions prior to 12.4. A malicious application may cause unexpected changes in memory shared between processes, leading to memory corruption.
A logic issue in macOS Tahoe 26 could allow an app to access sensitive user data. Apple addressed this with improved restrictions. The vulnerability was published on May 26, 2026, with no CVSS score or severity assigned. No known exploitation in the wild has been reported.
A race condition vulnerability in macOS could allow a malicious application to escalate privileges to root. Apple addressed this with additional validation in macOS Sequoia 15.7 and macOS Tahoe 26. The vulnerability was published on May 26, 2026. No CVSS score or severity rating has been assigned by NVD at this time. The issue is not listed in CISA's Known Exploited Vulnerabilities catalog.
An out-of-bounds read vulnerability in macOS was resolved through improved bounds checking. The issue, which could allow an application to trigger unexpected system termination, was addressed in macOS Tahoe 26. No CVSS score or severity rating has been assigned by NVD as of the CVE publication date. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog.