PatchSiren

Apple CVE debriefs · Page 10

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Apple CVE published 2026-03-25

CVE-2026-28838

Apple addressed a macOS permissions issue by adding additional sandbox restrictions. According to the vendor description, an app may be able to break out of its sandbox. Apple lists fixes for macOS Sonoma 14.8.5, macOS Sequoia 15.7.5, and macOS Tahoe 26.4. NVD rates the issue Medium severity (CVSS 5.3).

MEDIUM Apple CVE published 2026-03-25

CVE-2026-28833

CVE-2026-28833 is an Apple permissions/privacy issue where an app may be able to enumerate a user's installed apps. Apple says the issue is fixed in iOS 26.4, iPadOS 26.4, macOS Tahoe 26.4, and visionOS 26.4. The supplied NVD record rates the issue as medium severity and indicates a confidentiality impact, with no integrity or availability impact.

MEDIUM Apple CVE published 2026-03-25

CVE-2026-28826

Apple addressed CVE-2026-28826 as a logic issue with improved restrictions in macOS. According to Apple’s advisory links, the fix is available in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, and macOS Tahoe 26.4. The reported impact is a sandbox breakout by a malicious app, which makes this a meaningful endpoint-hardening issue for fleets that rely on macOS sandbox boundaries to contain untrusted or third-p [truncated]

LOW Apple CVE published 2026-03-25

CVE-2026-20684

Apple addressed a permissions issue in macOS Tahoe 26.4 that could allow an app to bypass Gatekeeper checks. The available advisory data points to a low-severity issue with limited integrity impact, but it is still worth prioritizing on systems running macOS Tahoe 26.0 through 26.3 because Gatekeeper is part of the software trust chain.

MEDIUM Apple CVE published 2026-03-25

CVE-2026-20657

Published on 2026-03-25, CVE-2026-20657 describes a buffer overflow in Apple software that was addressed with improved memory handling. Apple states that parsing a maliciously crafted file may lead to an unexpected app termination. The issue is fixed in iOS 18.7.7, iPadOS 18.7.7, iOS 26.4, iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, and visionOS 26.4.

HIGH Apple CVE published 2026-03-25

CVE-2026-20622

A privacy issue was addressed with improved handling of temporary files in macOS Sequoia 15.7.4, Sonoma 14.8.4, and Tahoe 26.3. This vulnerability, CVE-2026-20622, allows an app to capture a user's screen. The CVSS score is 7.5, indicating a high severity. Organizations and individuals using these macOS versions should prioritize patching to prevent potential screen capture by malicious apps. The vulnerab [truncated]

Known exploited Apple CVE published 2026-03-20

CVE-2025-43520

CVE-2025-43520 is a CISA Known Exploited Vulnerabilities (KEV) entry for Apple Multiple Products. The supplied corpus describes the issue as a classic buffer overflow and places it in CISA's catalog of vulnerabilities requiring urgent remediation. Because the source set here does not include the Apple advisory text, affected versions and deeper technical impact are not stated in this debrief. Treat the is [truncated]

Known exploited Apple CVE published 2026-03-20

CVE-2025-43510

CVE-2025-43510 is a CISA Known Exploited Vulnerabilities (KEV) entry for an Apple Multiple Products improper locking vulnerability. CISA added it on 2026-03-20 and set a remediation due date of 2026-04-03. The supplied corpus does not provide affected versions, severity, or detailed technical impact, so the safest interpretation is operational: treat this as a confirmed exploited issue and follow Apple’s [truncated]

Known exploited Apple CVE published 2026-03-20

CVE-2025-31277

CVE-2025-31277 is an Apple buffer overflow vulnerability affecting multiple products and included in CISA’s Known Exploited Vulnerabilities catalog. In the supplied corpus, CISA added the entry on 2026-03-20 and set a remediation due date of 2026-04-03, which makes this a time-sensitive defensive item for Apple asset owners. The provided material does not include a CVSS score or the specific affected prod [truncated]

Known exploited Apple CVE published 2026-03-05

CVE-2023-43000

CVE-2023-43000 is a use-after-free vulnerability affecting Apple Multiple Products and is listed in CISA’s Known Exploited Vulnerabilities catalog, which means it should be treated as actively exploited. The supplied corpus does not identify the specific Apple component(s), attack path, or public exploitation details, so remediation should rely on Apple’s vendor guidance and CISA’s KEV timeline.

Known exploited Apple CVE published 2026-03-05

CVE-2023-41974

CVE-2023-41974 is a use-after-free vulnerability affecting Apple iOS and iPadOS. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-03-05, which indicates confirmed real-world abuse and raises the remediation priority for any organization that manages Apple mobile devices. The supplied sources do not provide component-level technical detail, so defenders should treat the vulnerability as [truncated]

Known exploited Apple CVE published 2026-03-05

CVE-2021-30952

CVE-2021-30952 is an Apple multiple-products integer overflow or wraparound vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. Because it is in KEV, defenders should treat it as a priority remediation item even though the supplied corpus does not include affected product versions or a CVSS score. Follow Apple’s vendor guidance and the CISA due date to reduce exposure.

Known exploited Apple CVE published 2026-02-12

CVE-2026-20700

CVE-2026-20700 is a CISA Known Exploited Vulnerabilities (KEV) entry for an Apple multiple products buffer overflow vulnerability. The available corpus does not provide product-specific technical detail or a CVSS score, but it does confirm that CISA added the issue to KEV on 2026-02-12 and set a remediation due date of 2026-03-05. Treat this as an urgent defensive priority and follow Apple’s vendor instru [truncated]

CRITICAL Apple CVE published 2026-02-11

CVE-2026-20677

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-02-11T23:16:10.107Z and has not been modified since then. This race condition vulnerability, addressed with improved handling of symbolic links in Apple products, affects multiple platforms including iOS, iPadOS, macOS, and visionOS. The issue allows a shortcut to potentially bypass sandbox restriction [truncated]

HIGH Apple CVE published 2026-02-11

CVE-2026-20652

CVE-2026-20652 is a denial-of-service vulnerability in Apple Safari. The issue was addressed with improved memory handling. This vulnerability affects multiple Apple products, including Safari, iOS, iPadOS, macOS, and visionOS. A remote attacker may be able to cause a denial-of-service. The CVE was published on 2026-02-11 and modified on 2026-06-30.

MEDIUM Apple CVE published 2026-02-11

CVE-2026-20636

CVE-2026-20636 is a vulnerability in Apple Safari and other products that could lead to an unexpected process crash when processing maliciously crafted web content. The issue was addressed with improved memory handling. This vulnerability affects multiple Apple products, including Safari, iOS, iPadOS, macOS, and visionOS. The CVSS score for this vulnerability is 6.5, indicating a medium severity level. Th [truncated]

MEDIUM Apple CVE published 2026-02-11

CVE-2026-20635

CVE-2026-20635 is a vulnerability in Apple Safari and other products that could lead to an unexpected process crash when processing maliciously crafted web content. The issue was addressed with improved memory handling. This vulnerability affects multiple Apple products, including Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The CVSS score for this vulnerability is 4.3, indicating a medium sev [truncated]

MEDIUM Apple CVE published 2026-02-11

CVE-2026-20627

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-02-11T23:16:06.187Z and has not been modified since then. The issue involves environment variable handling, addressed with improved validation in iOS 26.3, iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3, and watchOS 26.3. An app may access sensitive user data du [truncated]

HIGH Apple CVE published 2026-02-11

CVE-2026-20617

CVE-2026-20617 is a race condition vulnerability in Apple products, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The issue, addressed in various updates such as iOS 26.3 and macOS Sequoia 15.7.4, allows an app to gain root privileges. Organizations should apply patches immediately to prevent potential attacks. This includes enterprises, consumers, and managed service providers. The CVE recor [truncated]

HIGH Apple CVE published 2026-02-11

CVE-2026-20615

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-02-11T23:16:05.060Z and has not been modified since then. The NVD entry is currently Modified. This path handling issue was addressed with improved validation in iOS, iPadOS, macOS, and visionOS, potentially allowing an app to gain root privileges through malicious execution. Further review of system l [truncated]

MEDIUM Apple CVE published 2026-02-11

CVE-2026-20608

CVE-2026-20608 is a vulnerability affecting Apple Safari and other products, including iOS, iPadOS, macOS, and visionOS. The issue was addressed through improved state management and is fixed in various versions of these products. Processing maliciously crafted web content may lead to an unexpected process crash. The CVSS score for this vulnerability is 5.5, with a severity rating of MEDIUM. Apple has pro [truncated]

MEDIUM Apple CVE published 2026-02-11

CVE-2025-46310

A state management vulnerability in macOS allows attackers with root privileges to delete protected system files. Apple addressed this through improved state management in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, and macOS Tahoe 26. The CVSS 3.1 vector (AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H) indicates a local attack vector requiring high privileges, with high impact to integrity and availability but no co [truncated]

MEDIUM Apple CVE published 2026-02-11

CVE-2025-43417

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-02-11T23:16:02.200Z and has not been modified since then. This CVE-2025-43417 involves a path handling issue addressed with improved logic in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, and macOS Tahoe 26.2. An app may be able to access user-sensitive data due to this vulnerability. Organizations and in [truncated]

MEDIUM Apple CVE published 2026-02-11

CVE-2025-43403

An authorization issue in macOS, addressed through improved state management, could allow an application to access sensitive user data. The vulnerability affects macOS versions prior to 14.8.4 (Sonoma) and versions 15.0 through 15.7.3 (Sequoia). Apple has released security updates for macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, and macOS Tahoe 26 to remediate this flaw. The CVSS 3.1 vector indicates a loca [truncated]

Known exploited Apple CVE published 2025-12-15

CVE-2025-43529

CVE-2025-43529 is listed by CISA as a known exploited vulnerability affecting Apple Multiple Products and described as a WebKit use-after-free issue. Because it appears in the KEV catalog, defenders should treat it as an urgent patching and mitigation priority. The supplied corpus does not include affected versions, exploitation mechanics, or vendor fix details, so the safest response is to follow the lin [truncated]

Known exploited Apple CVE published 2025-10-20

CVE-2022-48503

CVE-2022-48503 is listed by CISA as a Known Exploited Vulnerability affecting multiple Apple products. The public record provided here does not include a detailed technical flaw description or CVSS score, but KEV inclusion means defenders should treat it as actively exploited and prioritize Apple’s vendor guidance and remediation steps. CISA added it to the KEV catalog on 2025-10-20 with a remediation due [truncated]

LOW Apple CVE published 2025-09-15

CVE-2025-43357

CVE-2025-43357 is a LOW-severity privacy issue in Apple operating systems where an app may be able to fingerprint the user. The vulnerability stems from insufficient redaction of sensitive information, allowing applications to potentially collect identifying characteristics about the user or device. Apple addressed this through improved redaction mechanisms in security updates released September 2025. The [truncated]

Known exploited Apple CVE published 2025-08-21

CVE-2025-43300

CVE-2025-43300 is an Apple out-of-bounds write vulnerability affecting iOS, iPadOS, and macOS. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-08-21, which makes this a high-priority remediation item for managed Apple fleets. The KEV entry sets a due date of 2025-09-11, so defenders should treat Apple’s official guidance as time-sensitive and validate remediation across endpoints and [truncated]

Known exploited Apple CVE published 2025-06-16

CVE-2025-43200

CVE-2025-43200 is listed by CISA as a Known Exploited Vulnerability affecting Apple Multiple Products. In the supplied corpus, the issue is identified as an Apple vulnerability with no public technical specifics, but CISA’s KEV entry confirms it is considered actively exploited. The remediation deadline associated with the KEV entry is 2025-07-07, based on the 2025-06-16 addition date.

Known exploited Apple CVE published 2025-04-17

CVE-2025-31201

CVE-2025-31201 is listed by CISA in the Known Exploited Vulnerabilities catalog for Apple Multiple Products, with the vulnerability described as an arbitrary read and write issue. Because CISA has identified it as known exploited, organizations should treat remediation as urgent and prioritize Apple-provided mitigations or updates across managed fleets. The supplied corpus does not include Apple’s full ad [truncated]